HomeSecurityFive Eyes: Warns of exploitation of Ivanti vulnerabilities

Five Eyes: Warns of exploitation of Ivanti vulnerabilities

The Five Eyes has issued a new cybersecurity warning ,focusing on the risks posed by widely known vulnerabilities in the Ivanti Connect Secure and Ivanti Policy Secure portals.

Ivanti vulnerabilities

Furthermore, it highlights the possibility of misleading the Integrity Check Tool (ICT) in order to provide a false sense of security.

See also: Ivanti: Massive exploitation of vulnerability by cybercriminals

"Ivanti ICT is not sufficient to detect compromise and that a cyber may be able to gain root-level persistence despite the factory reset version," according to Five Eyes.

To date, Ivanti has reported five vulnerabilities affecting its products as of January 10, 2024. Of these, four have been actively exploited by various threat actors to develop malware.

CVE-2023-46805 (CVSS score: 8.2) – Authentication Bypass Vulnerability

CVE-2024-21887 (CVSS score: 9.1) – Command injection vulnerability

CVE-2024-21888 (CVSS score: 8.8) – Privilege escalation vulnerability

CVE-2024-21893 (CVSS score: 8.2) – SSRF vulnerability in SAML component

CVE-2024-22024 (CVSS score: 8.3) – XXE vulnerability in SAML component

Mandiant -excluded directory at /data/runtime/cockpit/diskAnalysis.

In the past few weeks, Eclypsium reported that directory exclusions have skipped scanning a dozen directories, allowing an attacker to place backdoors and breach integrity checks.

“The safest course of action for network defenders is to assume that a sophisticated threat actor can develop rootkit-level persistence on a device that has been reset and remains idle for an arbitrary period of time,” agencies from Australia, Canada, New Zealand, the United Kingdom and the United States said.

Read more: DSLog backdoor installed via SSRF vulnerability in Ivanti

They also encouraged organizations to consider the significant risk access and to insist on the use of Ivanti Connect Secure and Ivanti Policy Secure gateways when evaluating the continued operation of these devices in an enterprise environment.

Ivanti responded that it is not aware of any incidents where the threat remained after applying security updates and performing a factory reset. In addition, a new version of ICT is being released that offers additional visibility into a customer's device and all files on the system.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS