Skip to main content

Critical vulnerabilities could allow an attacker to bypass admin authentication and execute arbitrary commands on the appliance

Summary

Critical vulnerabilities could allow an attacker to bypass admin authentication and execute arbitrary commands on the appliance

Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

Ivanti has released security advisories addressing two vulnerabilities affecting the Ivanti Cloud Services Appliance (CSA). The Ivanti CSA is an Internet appliance that provides secure communication and functionality over the Internet. It falls under the primary product of Ivanti Endpoint Manager, but security fixes are maintained separately.

Chained together, the two vulnerabilities can allow an attacker to achieve remote code execution (RCE) on the appliance. 

Remediation advice

Affected organisations are strongly encouraged to review Security Advisory Ivanti CSA 4.6 (Cloud Services Appliance) (CVE-2024-8963) and Security Advisory Ivanti Cloud Service Appliance (CSA) (CVE-2024-8190) for guidance to apply any relevant security updates.

Definitive source of threat updates

CVE Vulnerabilities

Last edited: 20 September 2024 2:19 pm