Ivanti warns high severity CSA flaw is now exploited in attacks
ID: a15399f1-75de-538f-9764-490ea1c79839
STIX ID: report--a15399f1-75de-538f-9764-490ea1c79839
Feed Name: Bleeping Computer
Threat Score
Ivanti disclosed CVE-2024-8190, a high-severity command-injection RCE in Cloud Service Appliance (CSA) 4.6 that is actively being exploited against a limited set of customers; CISA has added the flaw to its Known Exploited Vulnerabilities catalog and directed federal agencies to patch by October 4. Ivanti urges customers to upgrade to CSA 5.0 (CSA 4.6 is EOL), review administrative access and broker logs, and check EDR alerts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
