Ivanti patches exploited admin command execution flaw
ID: 03ee4049-5d2a-5eae-85e5-4713118de81e
STIX ID: report--03ee4049-5d2a-5eae-85e5-4713118de81e
Feed Name: The Register (Security)
CISA added Ivanti CSA CVE-2024-8963 (path traversal, CVSS 9.4) to its KEV catalog after limited customer exploitation was observed; the bug can expose restricted functionality and, if chained with an earlier command-injection flaw (CVE-2024-8190), enable administrative command execution. Ivanti has released a patch (last backport for 4.6) and urges affected customers to patch or upgrade to 5.0, review broker logs/EDR for signs of compromise, and rebuild impacted appliances if intrusion is detected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
