HomeSecurityIvanti: CSA vulnerability used in attacks

Ivanti: CSA vulnerability used in attacks

Ivanti has confirmed that a serious vulnerability in its Cloud Services Appliance (CSA) is now being actively exploited for cyberattacks .

Ivanti CSA vulnerability

“At the time of the disclosure on September 10, we were not aware that the vulnerability against customers. In the September 13 update, the exploitation against a limited number of customers, following public disclosure,” said in an update added to its August security advisory.

“Dual -homed CSA configurations with ETH-0 as the internal network are at significantly reduced risk of exploitation,” says Ivanti.

The company advises administrators to review configuration settings and access permissions for any new or modified administrator user to detect potential exploit attempts. It is also recommended to review any alerts from EDR or other security.

See also: Citrix warns of vulnerabilities in Workspace for Windows

According to Ivanti, the vulnerability in the Cloud Services Appliance is tracked as CVE-2024-8190 and allows attackers, with administrator privileges, to remotely execute code on vulnerable devices running Ivanti CSA 4.6 via command injection.

Ivanti advises customers to upgrade from CSA 4.6.x (which has reached End-of-Life status) to CSA 5.0 (which is still supported).

“Customers on CSA 4.6 Patch 518 can also update to Patch 519. But as this product has entered its end of life, the preferred path is to upgrade to CSA 5.0. Customers already on CSA 5.0 do not need to take any further action,” the company added.

Ivanti CSA is a security product that acts as a gateway to provide external users with secure access to internal enterprise resources.

See also: Apple fixes 'GAZEploit' vulnerability in Vision Pro

Federal agencies are asked to update their systems by October 4.

Last week, Ivanti patched another serious vulnerability in its Endpoint Management software (EPM), which allows unauthorized attackers to perform remote code execution on the central server.

Ivanti: CSA vulnerability used in attacks

The impact of these vulnerabilities is significant, as they provide attackers with the ability to completely compromise affected systems. Ivanti advises all organizations using the affected versions to apply the updates immediately. In addition, it is recommended to monitor network traffic for any unusual activity that may indicate exploitation attempts. As cyber threats continue to evolve, timely addressing such vulnerabilities is crucial to maintaining security.

With the rise of sophisticated cyber attacks, it is no longer enough for organizations to rely solely on reactive measures to protect their systems. Proactive steps, such as regularly patching known vulnerabilities and implementing strong access controls, are essential to mitigate potential risks.

See also: Cisco IOS XR vulnerability allows hackers to gain elevated privileges

The exploitation of the new Ivanti CSA vulnerability serves as a reminder that attackers are constantly looking for new ways to infiltrate networks and compromise sensitive data. It also highlights the importance of staying vigilant and applying updates provided by software vendors.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS