CyberzSOC

Publication detail
← Back to advisories & guidance

2024-030: Critical Vulnerabilities in Ivanti Products ↗ source

March 21, 2024 CERT-EU Advisory

Summary

According to Ivanti, there is no evidence of these vulnerabilities being exploited in the wild. It is recommended upgrading affected software as soon as possible. The vulnerability CVE-2023-41724 , with a CVSS score of 9.6, affects Ivanti Standalone Sentry and could allow an unauthenticated attacker within the same physical or logical network to execute arbitrary commands on the underlying operating system of the appliance. [1] The vulnerability CVE-2023-46808 , with a CVSS score of 9.9, affects Ivanti Neurons for ITSM and could enable an authenticated remote user to perform file writes in sensitive directories which may allow execution of commands in the context of web application’s user. [2] The vulnerability CVE-2023-41724 impacts all supported versions of Ivanti Standalone Sentry (9.17.0, 9.18.0, and 9.19.0). The vulnerability CVE-2023-46808 impacts all supported versions of Ivanti Neurons for ITSM (2023.3, 2023.2 and 2023.1). CERT-EU strongly recommends updating affected software to the latest versions by following the instructions given by the vendor [1,2].

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2023-46808 9.9 Critical Ivanti ITSM An file upload vulnerability in Ivanti ITSM before 2023.4, allows an authenticated remote user to perform file writes to the server. Successful explo…
CVE-2023-41724 9.6 Critical Ivanti Sentry A command injection vulnerability in Ivanti Sentry prior to 9.19.0 allows unauthenticated threat actor to execute arbitrary commands on the underlyin…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.