{"id":168398,"date":"2024-09-14T15:45:27","date_gmt":"2024-09-14T15:45:27","guid":{"rendered":"https:\/\/securityaffairs.com\/?p=168398"},"modified":"2024-09-14T15:45:29","modified_gmt":"2024-09-14T15:45:29","slug":"u-s-cisa-adds-ivanti-csa-vulnerability-to-its-known-exploited-vulnerabilities-catalog","status":"publish","type":"post","link":"https:\/\/securityaffairs.com\/168398\/hacking\/u-s-cisa-adds-ivanti-csa-vulnerability-to-its-known-exploited-vulnerabilities-catalog.html","title":{"rendered":"U.S. CISA adds Ivanti Cloud Services Appliance Vulnerability to its Known Exploited Vulnerabilities catalog"},"content":{"rendered":"
<\/div>\n

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Ivanti Cloud Services Appliance Vulnerability to its Known Exploited Vulnerabilities catalog.<\/h2>\n\n\n\n

The U.S. Cybersecurity and Infrastructure Security Agency (CISA)\u00a0added<\/a> Ivanti Cloud Services Appliance OS Command Injection Vulnerability CVE-2024-8190<\/a> (CVSS score of 7.2) to its Known Exploited Vulnerabilities (KEV) catalog<\/a>.<\/p>\n\n\n\n

This week, Ivanti warned that recently patched flaw CVE-2024-8190 in Cloud Service Appliance (CSA) is being actively exploited in the wild.<\/p>\n\n\n\n

\u201cFollowing public disclosure, Ivanti has confirmed exploitation of this vulnerability in the wild. At the time of this update, we are aware of a limited number of customers who have been exploited.\u201d reads the update<\/a> provided by the company on September 13, 2024.<\/em><\/p>\n\n\n\n

An attacker can trigger this high-severity vulnerability to achieve remote code execution under specific conditions.<\/p>\n\n\n\n

\u201cAn OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.\u201d reads the advisory<\/a>. <\/em><\/p>\n\n\n\n

\u201cSuccessful exploitation could lead to unauthorized access to the device running the CSA. Dual-homed CSA configurations with ETH-0 as an internal network, as recommended by Ivanti, are at a significantly reduced risk of exploitation.\u201d<\/em><\/p>\n\n\n\n

Ivanti released a security update for Ivanti CSA 4.6 to address the vulnerability.<\/p>\n\n\n\n

The company note that CSA 4.6 is End-of-Life<\/a>, and no longer receives updates for OS or third-party libraries. Customers must upgrade to Ivanti CSA 5.0 for continued support, this version is not impacted by this vulnerability.  <\/p>\n\n\n\n

The company did not reveal details about the attacks exploiting the CVE-2024-8190 vulnerability.<\/gwmw><\/gwmw><\/gwmw><\/p>\n\n\n\n

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities<\/a>, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.<\/gwmw><\/gwmw><\/gwmw><\/gwmw><\/p>\n\n\n\n

Experts also recommend private organizations review the Catalog<\/a> and address the vulnerabilities in their infrastructure.<\/p>\n\n\n\n

CISA orders federal agencies to fix this vulnerability by\u00a0October 4, 2024.<\/p>\n\n\n\n

Follow me on Twitter: @securityaffairs<\/strong><\/a> and Facebook<\/strong><\/a> and Mastodon<\/strong><\/a><\/p>\n\n\n\n

Pierluigi Paganini<\/strong><\/a><\/p>\n\n\n\n

(<\/strong>SecurityAffairs<\/strong><\/a>\u00a0\u2013<\/strong>\u00a0hacking, CISA)<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Ivanti Cloud Services Appliance Vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA)\u00a0added Ivanti Cloud Services Appliance OS Command Injection Vulnerability CVE-2024-8190 (CVSS score of 7.2) to its Known Exploited Vulnerabilities (KEV) catalog. This week, Ivanti warned that recently patched flaw […]<\/p>\n","protected":false},"author":1,"featured_media":106349,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[3323,5,55],"tags":[4112,9508,9506,10918,14209,15368,687,841,1533],"class_list":["post-168398","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-breaking-news","category-hacking","category-security","tag-hacking","tag-hacking-news","tag-information-security-news","tag-it-information-security","tag-ivanti","tag-ivanti-cloud-service-appliance","tag-pierluigi-paganini","tag-security-affairs","tag-security-news"],"yoast_head":"\n杭州江阴科强工业胶带有限公司