Researchers at Fortinet FortiGuard Labs have observed that hackers are exploiting three vulnerabilities in the Ivanti Cloud Service Appliance (CSA) for malicious activities.

According to experts, the vulnerabilities have been used to gain unauthorized access to the CSA, for User enumeration, and to attempt to steal the credentials of these users.
"As observed, attackers exploit and combine zero-day vulnerabilities to gain access to the victim," said security researchers Faisal Abdul Malik Qureshi, John Simmons, Jared Betts, Luca Pugliese, Trent Healy, Ken Evans, and Robert Reyes.
See also: Ivanti: Warns of three new CSA vulnerabilities
The three Ivanti CSA vulnerabilities used in attacks are:
CVE-2024-8190 (CVSS score: 7.2/10) – A command injection vulnerability in the resource /gsb/DateTimeTab.php
CVE-2024-8963 (CVSS score: 9.4/10) – A path traversal vulnerability in the resource /client/index.php
CVE-2024-9380 (CVSS score: 7.2/10) – An authenticated command injection vulnerability affecting the resource reports.php.
In the next stage, the stolen credentials associated with gsbadmin and admin were used to exploit the command injection vulnerability affecting the /gsb/reports.php resource (for installing a web shell).
See also: CISA: Adds new Ivanti EPM vulnerability to KEV List
“On September 10, 2024, when the advisory for CVE-2024-8190 by Ivanti, the threat, which is still active on the customer's network, "patched" command injection vulnerabilities in the resources /gsb/DateTimeTab.php and /gsb/reports.php“.
“In the past, threat actors have patched vulnerabilities after exploiting them and gaining access to the victim's network to prevent any other attacker from gaining access to the vulnerable component and intervening in their attacks“.
Unknown attackers have also exploited CVE-2024-29824, a vulnerability in Ivanti Endpoint Manager (EPM). The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploitable Vulnerabilities (KEV) list in the first week of October 2024.

The implications of these vulnerabilities are significant, as they provide attackers with the ability to completely compromise affected systems. In addition to applying updates, it is recommended to monitor network traffic for any unusual activity that may indicate exploitation attempts. As threats continue to evolve, addressing such vulnerabilities in a timely manner is crucial to maintaining security.
See also: Ivanti warns of new CSA vulnerability
Organizations cannot simply rely on reactive measures to protect their systems. Proactive steps, such as regularly patching known vulnerabilities and implementing strong access, are essential to mitigate potential risks.
The Ivanti CSA exploit and combination of vulnerabilities serve as a reminder that attackers are constantly looking for new ways to penetrate networks and compromise sensitive data. It also highlights the importance of staying vigilant and applying updates provided by software vendors.
Source: thehackernews.com
