Tuesday , September 17 2024
ivanti

(CVE-2024-7569 and CVE-2024-7570)
Ivanti flags Critical Fixes for ITSM Vulnerabilities

Ivanti issued a security advisory about two important vulnerabilities in its Neurons for IT Service Management (ITSM) platform. Customers using the on-premise version should act quickly. The vulnerabilities (CVE-2024-7569 and CVE-2024-7570) affect Ivanti Neurons for ITSM versions 2023.4 and older, putting them at risk of unauthorized data access and system compromise.

Vulnerabilities and Potential Impacts:

Alert! Google Fixes GCP Composer Flaw

Tenable Research found and fixed a remote code execution (RCE) vulnerability, called CloudImposer, in Google Cloud Platform (GCP). This flaw...
Read More
Alert! Google Fixes GCP Composer Flaw

CTF in Bangladesh: Unveiling Challenges, Opportunities and remedies

In this article, we won’t dive too deep into the technical aspects of Capture The Flag (CTF) competitions. Instead, we...
Read More
CTF in Bangladesh: Unveiling Challenges, Opportunities and remedies

Bitdefender blog post
Medusa target Fortinet flaw (CVE-2023-48788) for Ransomware Attacks

A recent Bitdefender report reveals that Medusa is still actively attacking and has created a notable presence on both the...
Read More
Bitdefender blog post  Medusa target Fortinet flaw (CVE-2023-48788) for Ransomware Attacks

Ivanti alerts ongoing exploitation of recently patched CAV

Ivanti warned that a recently fixed security flaw in its Cloud Service Appliance (CSA) is being actively exploited. CVE-2024-8190 is...
Read More
Ivanti alerts ongoing exploitation of recently patched CAV

CISA unveils 25 new advisories for Industrial Control Systems

CISA issued 25 ICS advisories on September 12, 2024, detailing current security issues, vulnerabilities, and exploits in Industrial Control Systems....
Read More
CISA unveils 25 new advisories for Industrial Control Systems

Intel Issues Alert on 20+ Vulnerabilities, Urges Firmware Updates

Intel announced over 20 vulnerabilities in its processors and products in security advisories released on Tuesday. The chip giant has...
Read More
Intel Issues Alert on 20+ Vulnerabilities, Urges Firmware Updates

Urgent: GitLab Patches flaws allowing unapproved pipeline Job Execution

GitLab released security updates on Wednesday to fix 17 vulnerabilities, including a critical issue that lets attackers run pipeline jobs...
Read More
Urgent: GitLab Patches flaws allowing unapproved pipeline Job Execution

Fortinet admits data breach after hacker claims to steal 440GB

Fortinet confirmed a data breach after a threat actor claimed to have stolen 440GB of files from its Microsoft SharePoint...
Read More
Fortinet admits data breach after hacker claims to steal 440GB

Gov.t issues high alert on android devices

Indian Computer Emergency Response Team (CERT-In) issued a high-severity alert for android devices on September 11, 2024 highlighting the vulnerabilities...
Read More
Gov.t issues high alert on android devices

TD Bank fined $28 million for sharing customer data

Because of disclosing incorrect and negative data, The Consumer Financial Protection Bureau (CFPB) on Wednesday fined TD Bank, one of...
Read More
TD Bank fined $28 million for sharing customer data

Vulnerability CVE-2024-7569 has a high severity score of 9.6. It allows an unauthenticated attacker to access the OIDC client secret through exposed debug information, which could lead to unauthorized access to sensitive information within the ITSM environment.

The vulnerability is a big concern for organizations that use OIDC authentication in their ITSM systems. If the client secret is exposed, the authentication process could be compromised. This means attackers could pretend to be real users or services.

The second vulnerability, CVE-2024-7570, has a CVSS score of 8.3 and stems from the improper validation of certificates in Ivanti Neurons for ITSM. This weakness allows a malicious actor positioned in the Man-in-the-Middle (MITM) to create a harmful token, which grants undesired access to the ITSM system, posing as any user. The repercussions of this vulnerability are extremely grave, as unauthorized access, data manipulation, or even the critical disruption of IT services can occur.

Patch Availability and Urgency for On-Premise Customers:

Ivanti has fixed vulnerabilities in their cloud-based Ivanti Neurons for ITSM as of August 4, protecting cloud customers. On-premise customers using versions 2023.4 and earlier should apply the available patches quickly to reduce the risks from these vulnerabilities.

Impact and Recommendations:

These vulnerabilities affect customers using Ivanti Neurons for ITSM with OIDC authentication. Ivanti hasn’t seen these vulnerabilities being exploited, but it’s important to act quickly due to the critical nature of the issues.

Check Also

GitLab

Urgent: GitLab Patches flaws allowing unapproved pipeline Job Execution

GitLab released security updates on Wednesday to fix 17 vulnerabilities, including a critical issue that …

Leave a Reply

Your email address will not be published. Required fields are marked *