THREAT LEVEL - HIGH

28-01-2025

Ivanti Cloud Services Appliance Zero-Day Vulnerabilities

Threat Level Description

IthacaLabs has maintained the Threat Level (High) adding a new observation:

An attack is highly likely. Addressing the broad nature of the threat in order to reach an acceptable risk level, requires additional and sustainable protective security measures combined with specific business and geographical vulnerabilities and judgments.

Description

We have observed that multiple zero-day vulnerabilities impacting Ivanti Cloud Services Appliance (CSA) have been identified.

An attacker, by exploiting these vulnerabilities, could gain initial access to target systems and perform remote code execution (RCE), allowing them to obtain credentials and implant webshells on victim networks.

The vulnerability, tracked as CVE-2024-9379, is an SQL injection in the admin web console of Ivanti CSA that allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.

The vulnerability, tracked as CVE-2024-9380, is an OS command injection vulnerability that allows a remote authenticated attacker with admin privileges to obtain remote code execution.

The vulnerability, tracked as CVE-2024-9381, is a path traversal vulnerability that allows a remote authenticated attacker with admin privileges to bypass restrictions.

The vulnerability, tracked as CVE-2024-8963, is a path traversal vulnerability that allows a remote unauthenticated attacker to access restricted functionality.

The vulnerability, tracked as CVE-2024-8190, is an OS command injection vulnerability and before that allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.

Ivanti has confirmed that these vulnerabilities have been actively exploited in the wild. They were used to deploy webshells on victim networks, granting attackers persistent remote access.

Affected Products

Ivanti Cloud Services Appliance (CSA):

  • CSA 5.0 Versions < 5.0.2 (CVE-2024-9379, CVE-2024-9380, CVE-2024-9381)
  • CSA 4.6 Versions < Patch 519 (CVE-2024-8963)
  • CSA 4.6 Patch 518 and earlier (CVE-2024-8190)

Recommendation(s)

You should proceed to apply all security patches provided by the vendor immediately.

Furthermore, you should consider restricting access to the management interface to trusted internal IP addresses only, preventing unauthorized external access from the internet.

You should understand the importance of security updates, and the urgency with which they should be applied, no matter how large or small your organization is. It is very important to apply an efficient patch management solution and always have enabled an active event security logging and practice event monitoring. To protect the valuable assets of your business and be compliant with the relevant industry regulations requires a comprehensive approach to the management of risk, including Penetration Testing at least annually and upon significant changes.

References:

SIGN UP

Get the latest Threat Alerts in your inbox.