Tag: Ivanti Cloud Appliance

Critical Ivanti Cloud Appliance Vulnerability Exploited in Active Cyberattacks
News

Critical Ivanti Cloud Appliance Vulnerability Exploited in Active Cyberattacks

According to Ivanti, there has been active exploitation of a severe security weakness affecting Cloud Service Appliances (CSA) in the field. With a maximum CVSS score of 10.0, the new vulnerability, with the CVE identifier CVE-2024-8963, has a score of 9.4. The business "incidentally addressed" it in CSA 5.0 and CSA 4.6 Patch 519. The business stated in a bulletin on Thursday that Path Traversal in the Ivanti CSA before to 4.6 Patch 519 permits a remote, unauthenticated attacker to access restricted capabilities. The vulnerability might be combined with CVE-2024-8190 (CVSS score: 7.2), according to the report, which would allow an attacker to get around admin authentication and use the appliance to carry out arbitrary operations read more about Critical Ivanti Cloud Appliance Vul...