ZeroHour
Security Affairspublished ()ingested @securityaffairs

Ivanti Cloud Service Appliance flaw is being actively exploited

criticalExploit / PoC exploited in the wildimportance 60CVE-2024-8190CVE-2024-29847

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-29847
Unauthenticated Deserialization RCE in Ivanti Endpoint Manager Agent Portal

CVE-2024-29847 is a deserialization of untrusted data flaw (CWE-502) in the agent portal of Ivanti Endpoint Manager (EPM). A remote, unauthenticated attacker can send maliciously crafted serialized data to the agent portal, and processing of that input results in remote code execution on the EPM server. Because EPM core servers typically hold privileged roles in enterprise Windows environments, successful exploitation could provide a foothold for broader network compromise. Organizations running EPM before the 2022 SU6 release, or before the 2024 September update, are affected. The flaw was patched in September 2024 with no public PoC or confirmed in-the-wild exploitation yet, but its high EPSS (52.9%, 99th percentile) suggests exploitation is likely within 30 days, and it arrives amid separate active exploitation of other Ivanti products (the Cloud Service Appliance), raising attacker interest in Ivanti software generally.

Do: Upgrade to Ivanti EPM 2022 SU6 if on the 2022 release line, or apply the September 2024 update if on the 2024 line. Restrict network access to the EPM agent portal to trusted management segments and review EPM servers for signs of compromise given the current attention on Ivanti products. Review Ivanti's September 2024 EPM advisory for additional vulnerabilities fixed at the same time.

9.853%
  • Ivanti Endpoint Manager (EPM) - agent portal All versions before 2022 SU6
  • Ivanti Endpoint Manager (EPM) - agent portal All 2024-line versions before the September 2024 update
largetens of thousands of enterprise EPM deployments (internet-exposed footprint likely smaller)
CVE-2024-8190
OS Command Injection RCE in Ivanti Cloud Services Appliance 4.6

Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before contain an OS command injection flaw (CWE-78) that allows a remote, authenticated attacker to achieve remote code execution. The attacker must already hold administrator-level privileges on the appliance, and exploitation is triggered by sending crafted input to the appliance over the network. Successful exploitation yields arbitrary command execution on the CSA, and related reporting indicates nation-state actors have been exploiting Ivanti CSA flaws for network infiltration, including attacks on French government and telecom targets. Only organizations still running CSA 4.6.x are affected, and that product line has reached end-of-life and will not receive further security updates. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-13 and carries a very high EPSS score (88.5%, 100th percentile), signaling confirmed and likely ongoing exploitation in the wild.

Do: Because CSA 4.6.x has reached end-of-life, remove CSA 4.6.x from service or migrate to the supported 5.0.x line, as future 4.6.x flaws are unlikely to receive fixes. Given confirmed nation-state exploitation, hunt for signs of compromise such as unexpected admin sessions, processes, or network tunnels, and restrict internet exposure of any remaining 4.6.x appliances in the interim.

7.289% KEV
  • Ivanti Cloud Services Appliance 4.6 through Patch 518 (versions 4.6 Patch 518 and before)
moderateroughly 1,000–2,000 internet-exposed CSA appliances (public internet scan counts)
Full article290 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini September 14, 2024

Ivanti warned that recently patched flaw CVE-2024-8190 in Cloud Service Appliance (CSA) is being actively exploited in the wild.

Ivanti warned that a newly patched vulnerability, tracked as CVE-2024-8190 (CVSS score of 7.2), in its Cloud Service Appliance (CSA) is being actively exploited.

“Following public disclosure, Ivanti has confirmed exploitation of this vulnerability in the wild. At the time of this update, we are aware of a limited number of customers who have been exploited.” reads the update provided by the company on September 13, 2024.

An attacker can trigger this high-severity vulnerability to achieve remote code execution under specific conditions.

“An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.” reads the advisory

“Successful exploitation could lead to unauthorized access to the device running the CSA. Dual-homed CSA configurations with ETH-0 as an internal network, as recommended by Ivanti, are at a significantly reduced risk of exploitation.”

Ivanti released a security update for Ivanti CSA 4.6 to address the vulnerability.

The company note that CSA 4.6 is End-of-Life, and no longer receives updates for OS or third-party libraries. Customers must upgrade to Ivanti CSA 5.0 for continued support, this version is not impacted by this vulnerability.  

The company did not reveal details about the attacks exploiting the CVE-2024-8190 vulnerability.

Recently cybersecurity firm Horizon3.ai published a technical analysis of an Ivanti Endpoint Manager AgentPortal Deserialization of Untrusted Data issue, tracked as CVE-2024-29847, that could allow remote code execution.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Cloud Service Appliance) 



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/168388/hacking/ivanti-csa-cve-2024-8190.html