HomeSecurityHackers exploit three Ivanti CSA vulnerabilities

Hackers exploit three Ivanti CSA vulnerabilities

Researchers at Fortinet FortiGuard Labs have observed that hackers are exploiting three vulnerabilities in the Ivanti Cloud Service Appliance (CSA) for malicious activities.

Ivanti Service Appliance (CSA) vulnerabilities,

According to experts, the vulnerabilities have been used to gain unauthorized access to the CSA, for User enumeration, and to attempt to steal the credentials of these users.

"As observed, attackers exploit and combine zero-day vulnerabilities to gain access to the victim," said security researchers Faisal Abdul Malik Qureshi, John Simmons, Jared Betts, Luca Pugliese, Trent Healy, Ken Evans, and Robert Reyes.

See also: Ivanti: Warns of three new CSA vulnerabilities

The three Ivanti CSA vulnerabilities used in attacks are:

CVE-2024-8190 (CVSS score: 7.2/10) – A command injection vulnerability in the resource /gsb/DateTimeTab.php

CVE-2024-8963 (CVSS score: 9.4/10) – A path traversal vulnerability in the resource /client/index.php

CVE-2024-9380 (CVSS score: 7.2/10) – An authenticated command injection vulnerability affecting the resource reports.php.

In the next stage, the stolen credentials associated with gsbadmin and admin were used to exploit the command injection vulnerability affecting the /gsb/reports.php resource (for installing a web shell).

See also: CISA: Adds new Ivanti EPM vulnerability to KEV List

“On September 10, 2024, when the advisory for CVE-2024-8190 by Ivanti, the threat, which is still active on the customer's network, "patched" command injection vulnerabilities in the resources /gsb/DateTimeTab.php and /gsb/reports.php“.

“In the past, threat actors have patched vulnerabilities after exploiting them and gaining access to the victim's network to prevent any other attacker from gaining access to the vulnerable component and intervening in their attacks“.

Unknown attackers have also exploited CVE-2024-29824, a vulnerability in Ivanti Endpoint Manager (EPM). The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploitable Vulnerabilities (KEV) list in the first week of October 2024.

Hackers exploit three Ivanti CSA vulnerabilities

The implications of these vulnerabilities are significant, as they provide attackers with the ability to completely compromise affected systems. In addition to applying updates, it is recommended to monitor network traffic for any unusual activity that may indicate exploitation attempts. As threats continue to evolve, addressing such vulnerabilities in a timely manner is crucial to maintaining security.

See also: Ivanti warns of new CSA vulnerability

Organizations cannot simply rely on reactive measures to protect their systems. Proactive steps, such as regularly patching known vulnerabilities and implementing strong access, are essential to mitigate potential risks.

The Ivanti CSA exploit and combination of vulnerabilities serve as a reminder that attackers are constantly looking for new ways to penetrate networks and compromise sensitive data. It also highlights the importance of staying vigilant and applying updates provided by software vendors.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS