Latest Ivanti Cloud Services Appliance Vulnerability: CVE-2024-8963 #

Ivanti has issued an advisory for a path traversal vulnerability discovered in their Cloud Services Appliance product. 

What is the impact? #

Successful exploitation of this vulnerability would allow an unauthenticated attacker "access to restricted functionality". When combined with the vulnerability disclosed last week, an attacker could "bypass admin authentication and execute arbitrary code on the appliance".

CVE-2024-8963 is rated critical with a CVSS score of 9.4.

Note that the vendor has indicated that there is evidence that this vulnerability is being exploited in the wild.

Are updates or workarounds available? #

Ivanti has indicated that the affected version of the product, version 4.6, is End-of-Life (EOL). According to Ivanti, updates or security patches will not be made available. Customers are urged to upgrade to version 5.0.

How to find potentially vulnerable systems with runZero #

From the Services Inventory, use the following query to locate systems running potentially vulnerable software:

protocol:http and html.title:="Ivanti(R) Cloud Services Appliance"

September 10, 2024 (CVE-2024-8190) #

Ivanti has issued an advisory for their Cloud Services Appliance product. Successful exploitation of this vulnerability would allow an attacker to execute arbitrary commands on the underlying operating system. Note that the attacker must be authenticated with Ivanti application administrator privileges to exploit this vulnerability.

CVE-2024-8190 is rated high with a CVSS score of 7.2.

Note that the vendor has indicated that there is evidence this vulnerability is being exploited in the wild.

Are updates or workarounds available? #

Ivanti has issued a patch for this vulnerability. Note that the affected version of the product, version 4.6, is considered end-of-life. Ivanti has indicated that no further updates or security patches will be provided for version 4.6 of this product and urges customers to upgrade to version 5.0.

How to find potentially vulnerable systems with runZero #

From the Services Inventory, use the following query to locate systems running potentially vulnerable software:

protocol:http and html.title:="Ivanti(R) Cloud Services Appliance"

Written by Rob King

Rob King is the Director of Security Research at runZero. Over his career Rob has served as a senior researcher with KoreLogic, the architect for TippingPoint DVLabs, and helped get several startups off the ground. Rob helped design SC Magazine's Data Leakage Prevention Product of the Year for 2010, and was awarded the 3Com Innovator of the Year Award in 2009. He has been invited to speak at BlackHat, Shmoocon, SANS Network Security, and USENIX.

More about Rob King

Written by runZero Team

Due to the nature of their research and out of respect for their privacy, runZero team members prefer to remain anonymous. Their work is published under the runZero name.

More about runZero Team
Subscribe Now

Get the latest news and expert insights delivered in your inbox.

Welcome to the club! Your subscription to our newsletter is successful.


Related Articles

Rapid Response
How to find FortiManager instances on your network
How to find FortiManager instances on your network using runZero
Rapid Response
How to find SolarWinds Web Help Desk services on your network
CISA has announced that CVE-2024-28987 is actively being exploited in SolarWinds' Web Help Desk software. Here's how to find potentially affected...
Rapid Response
How to find SuperMicro BMCs
Supermicro released a vulnerability advisory for a critical CVE that allows for remote code execution (CVE-2024-36435). Here's how to find impacted...
Rapid Response
How to find OpenPrinting CUPS services on your network
Several vulnerabilities within OpenPrinting CUPS potentially allow for remote code execution. Here's how to find impacted assets.

See Results in Minutes

Get complete visibility into IT, OT, & IoT — without agents, credentials, or hardware.

© Copyright 2024 runZero, Inc. All Rights Reserved