Updates address exploited vulnerabilities in Cloud Services Application and one critical vulnerability in Connect Secure and Policy Secure
Summary
Updates address exploited vulnerabilities in Cloud Services Application and one critical vulnerability in Connect Secure and Policy Secure
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Ivanti has released security advisories addressing vulnerabilities in multiple products.
Three vulnerabilities affecting Cloud Services Appliance (CSA) have been exploited by being chained together with previously patched vulnerability CVE-2024-8963.
Additionally, CVE-2024-37404 has a CVSSv3 score of 9.1 and is an improper input validation vulnerability in the admin portal of Ivanti Connect Secure or Ivanti Policy Secure. If exploited, a remote authenticated attacker could achieve remote code execution.
Remediation advice
Affected organisations are strongly encouraged to review the following security advisories and apply any relevant updates.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 9 October 2024 3:59 pm