Ivanti Zero-Day

10/09/2024 15:59 By Todd

Critical Security Alert: Vulnerabilities Possibly in Your Network Switches

We have been informed about three zero-day vulnerabilities identified in Ivanti's Connect Secure Appliance (CSA) that are being used in a dangerous attack chain.   Hackers are actively abusing these exploits in combination to take over networks and steal data. 


Ivanti has acknowledged these zero-days and is offering updates to their Connect Secure Appliance to resolve this issue. The active abuse of these vulnerabilities emphasizes the importance for organizations to apply these patches immediately as we expect to see this attack chain to be abused for data theft or even ransomware. 


QUICK POINTS: 


IMMEDIATE ACTION: 

  • Update devices accordingly: Ensure any devices that run the Connect Secure Appliance software are up to date with the latest version
  • Upgrade End-of-Life (EOL) devices: With the main devices being exploited being EOL, CSA 4.6 patch 518, admins are strongly advised to upgrade to the latest version, 5.0.2
  • Review and monitor: Review appliances and devices for any indicators of compromise, specifically for any modified or newly added admin users 

Todd

Added to cart
- There was an error adding to cart. Please try again.
Quantity updated
- An error occurred. Please try again later.
Deleted from cart
- Can't delete this product from the cart at the moment. Please try again later.