Ivanti has issued a warning regarding two new high-severity vulnerabilities in its Connect Secure and Policy secure solutions, identified as CVE-2024-21888 (CVSS score: 8.8) and CVE-2024-21893 (CVSS score: 8.2) respectively. Furthermore, the company has alerted that one of these vulnerabilities is actively being exploited in the wild.
The vulnerability CVE-2024-21888 allows attackers to gain admin privileges by exploiting a privilege escalation issue in the web component of Ivanti Connect Secure (9.x, 22.x) and Policy Secure (9.x, 22.x).
By infosecbulletin
/ Monday , June 24 2024
LockBit claimed that it breached Federal Reserve Board (Federalreserve.gov), the central banking system of the United States and exfiltrated 33...
Read More
By infosecbulletin
/ Monday , June 24 2024
Cyber attack compromised Indonesia's national data center, causing trouble with immigration checks at airports. Attacker demanded an $8 million ransom,...
Read More
By infosecbulletin
/ Sunday , June 23 2024
ESET Issued security patch for privilege escalation flaw in its Windows security products. This flaw, called CVE-2024-2003 (CVSS 7.3), was...
Read More
By infosecbulletin
/ Saturday , June 22 2024
A threat offer to sell a zero-day exploit for Atlassian's Jira in a underground forum. This exploit can be used...
Read More
By infosecbulletin
/ Friday , June 21 2024
The US plans to ban the sale of Kaspersky antivirus software due to its alleged ties to the Kremlin. Gina...
Read More
By infosecbulletin
/ Friday , June 21 2024
A group believed to be linked to China has hacked multiple telecom operators in an Asian country since 2021, according...
Read More
By infosecbulletin
/ Thursday , June 20 2024
Certified Information Systems Auditor (CISA) is a globally recognized professional certification for information systems audit, control, and security. It's offered...
Read More
By infosecbulletin
/ Thursday , June 20 2024
DataDog Security Labs found a worrying campaign targeting Amazon Web Services (AWS), showing a new wave of harmful activity aimed...
Read More
By infosecbulletin
/ Wednesday , June 19 2024
CISA and the FBI released guidance, Modern Approaches to Network Access Security, with support from other organizations including New Zealand’s...
Read More
By infosecbulletin
/ Tuesday , June 18 2024
On June 18, 2024, CISA released an advisory about Industrial Control Systems (ICS). These advisories give important information about security...
Read More
CVE-2024-21893 is a server-side request forgery vulnerability in SAML component of Connect Secure (9.x, 22.x), Policy Secure (9.x, 22.x) and Neurons for ZTA. An authenticated attacker can exploit this flaw to access restricted resources.
The company warns that the situation is still changing, and multiple threat actors can quickly adjust their tactics to exploit these issues in their campaigns.
“At the time of publication, the exploitation of CVE-2024-21893 appears to be targeted. Ivanti expects the threat actor to change their behavior and we expect a sharp increase in exploitation once this information is public – similar to what we observed on 11 January following the 10 January disclosure.” reads the advisory.
“Be aware that the situation is still evolving. Ivanti will update this knowledge base article as more information becomes available.”
The software firm suggests using the “mitigation.release.20240126.5.xml” file from the download portal as a temporary solution for CVE-2024-21888 and CVE-2024-21893.
In January 2024, Ivanti reported that hackers were using two new vulnerabilities to run commands on specific gateways.
Today, researchers from cybersecurity company Synacktiv analyzed a Rust malware called KrustyLoader, which was used by threat actors to exploit vulnerabilities.