CISA warns of hackers exploiting bug for end-of-life Ivanti product
ID: cc31d3ba-25b6-56f0-af14-783ec6cf71f2
STIX ID: report--cc31d3ba-25b6-56f0-af14-783ec6cf71f2
Feed Name: CyberScoop
Threat Score
CISA warns that Ivanti Cloud Service Appliance (CSA) versions 4.6 and below are affected by CVE-2024-8190, an OS command injection vulnerability that can lead to remote code execution if an attacker has admin privileges; Ivanti reports limited exploitation, recommends upgrading to CSA 5.0 and dual-homing configurations, and federal agencies must mitigate the issue within 60 days.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
