CyberzSOC

Publication detail
← Back to advisories & guidance

CISA and FBI Release Advisory on How Threat Actors Chained Vulnerabilities in Ivanti Cloud Service Applications ↗ source

January 22, 2025 CISA Alert
Co-sealed by: CISA, CSA, FBI

Summary

This advisory was crafted in response to exploitation of vulnerabilities— CVE-2024-8963 , an administrative bypass vulnerability; CVE-2024-9379 , a SQL injection vulnerability; and CVE-2024-8190 and CVE-2024-9380 , remote code execution vulnerabilities—in Ivanti Cloud Service Appliances (CSA) in September 2024. CISA, and the use of trusted third-party incident response data, found that threat actors chained the listed vulnerabilities to gain initial access, conduct remote code execution (RCE), obtain credentials, and implant webshells on victim networks. CISA and FBI strongly encourage network administrators and defenders to upgrade to the latest supported version of Ivanti CSA and to hunt for malicious activity on their networks using the detection methods and indicators of compromise (IOCs) provided in the advisory. All members of the cybersecurity community are also encouraged to visit CISA’s Known Exploited Vulnerabilities Catalog to help better manage vulnerabilities and keep pace with threat activity. For more information and guidance on protection against the most common and impactful threats, tactics, techniques, and procedures, visit CISA’s Cross-Sector Cybersecurity Performance Goals . This product is provided subject to this Notification and this Privacy & Use policy.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-8963 9.4 Critical Ivanti Cloud Services Appliance (CSA) Ivanti Cloud Services Appliance (CSA) contains a path traversal vulnerability that could allow a remote, unauthenticated attacker to access restricte…
CVE-2024-8190 7.2 High Ivanti Cloud Services Appliance Ivanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in the administrative console which can allow an authenticated a…
CVE-2024-9380 7.2 High Ivanti Cloud Services Appliance (CSA) Ivanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in the administrative console which can allow an authenticated a…
CVE-2024-9379 6.5 Medium Ivanti Cloud Services Appliance (CSA) Ivanti Cloud Services Appliance (CSA) contains a SQL injection vulnerability in the admin web console in versions prior to 5.0.2, which can allow a r…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.