InsighthubNews
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
Reading: Ivanti warns of campaign exploiting newly patched cloud appliance vulnerability
Share
Font ResizerAa
InsighthubNewsInsighthubNews
Search
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
© 2024 All Rights Reserved | Powered by Insighthub News
InsighthubNews > Technology > Ivanti warns of campaign exploiting newly patched cloud appliance vulnerability
Technology

Ivanti warns of campaign exploiting newly patched cloud appliance vulnerability

September 14, 2024 2 Min Read
Share
Cloud Appliance Vulnerability
SHARE

Ivanti has revealed that a newly fixed security flaw in its Cloud Service Appliance (CSA) has been exploited in the wild.

The high severity vulnerability in question is CVE-2024-8190 (CVSS score: 7.2), which could allow remote code execution under certain circumstances.

“An OS command injection vulnerability in Ivanti Cloud Services Appliance version 4.6 Patch 518 and earlier could allow a remote authenticated attacker to obtain remote code execution,” Ivanti noted in an advisory released earlier this week. “To exploit this vulnerability, an attacker would need to have administrator-level privileges.”

This flaw affects Ivanti CSA 4.6, which is now out of support and requires customers to upgrade to a supported version going forward, but the issue is resolved in CSA 4.6 patch 519.

“This is the last fix that Ivanti will backport to this version due to end of support,” the Utah-based IT software company added. “Customers should upgrade to Ivanti CSA 5.0 to continue receiving support.”

“CSA 5.0 is the only supported version and does not contain this vulnerability. Customers already running Ivanti CSA 5.0 do not need to take any additional action.”

On Friday, Ivanti updated its advisory, noting that it had observed exploitation of the vulnerability targeting a “limited number of customers.”

No further details about the attack or the identities of the threat actors who weaponized it have been released, but a number of other vulnerabilities in Ivanti products have been exploited in zero-day attacks by China-linked cyberespionage groups.

In response to this incident, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog and mandated that federal agencies patch it by October 4, 2024.

See also  Singapore Police arrest six hackers linked to global cybercrime ring

The disclosure comes at the same time that cybersecurity firm Horizon3.ai posted a detailed technical analysis of a critical deserialization vulnerability (CVE-2024-29847, CVSS score: 10.0) affecting Endpoint Manager (EPM) and leading to remote code execution.

Share This Article
Twitter Copy Link
Previous Article Greedfall 2 is a beautiful fantasy RPG that harkens back to BioWare's heyday Greedfall 2 is a beautiful fantasy RPG that harkens back to BioWare’s heyday
Next Article Trump says Steve Garvey made a "big mistake" by not seeking MAGA support in Senate race Trump says Steve Garvey made a “big mistake” by not seeking MAGA support in Senate race
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest News

The Solution is Cyber ​​Hygiene

The Solution is Cyber ​​Hygiene

Cybersecurity in healthcare has never been more urgent. As the…

September 19, 2024
mm

Enterprise LLM API: A top choice for powering LLM applications in 2024

Some big recent news stories have escalated the race for…

September 19, 2024
Authentication Bypass

GitLab fixes critical SAML authentication bypass vulnerability in CE and EE editions

GitLab has released a patch to address a critical flaw…

September 19, 2024
Chinese engineer indicted in US for years of cyberespionage targeting NASA and military

Chinese engineer indicted in US for years of cyberespionage targeting NASA and military

A Chinese national has been indicted in the United States…

September 19, 2024
IoT Botnet

New “Raptor Train” IoT Botnet Compromises Over 200,000 Devices Worldwide

Cybersecurity researchers have discovered a never-before-seen botnet made up of…

September 18, 2024

You Might Also Like

Intellexa Predator Spyware Operation
Technology

U.S. Treasury Department sanctions executives involved in Intellexa Predator spyware campaign

4 Min Read
mm
Technology

Intelligence refinement: The strategic role of fine-tuning in the evolution of LLaMA 3.1 and Orca 2

10 Min Read
DragonRank Black Hat SEO Campaign
Technology

DragonRank Black Hat SEO Campaign Targets IIS Servers in Asia and Europe

5 Min Read
mm
Technology

What the release of OpenAI’s o1 model says about changing AI strategies and visions

9 Min Read
InsighthubNews
InsighthubNews

Welcome to InsighthubNews, your reliable source for the latest updates and in-depth insights from around the globe. We are dedicated to bringing you up-to-the-minute news and analysis on the most pressing issues and developments shaping the world today.

  • Home
  • Celebrity
  • Environment
  • Business
  • Crypto
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
  • World News
  • Politics
  • Technology
  • Sports
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2024 All Rights Reserved | Powered by Insighthub News

Welcome Back!

Sign in to your account

Lost your password?