Site icon TheCyberThrone

CISA KEV Update Part IV – October 2024

Advertisements

The US CISA has added below vulnerabilities to its Known exploited vulnerabilities catalog based on the evidence of active exploitation

CVE-2024-23113

With a CVSS score of 9.8, Fortinet FortiOS, FortiPAM, FortiProxy, and FortiWeb contain a format string vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-9379

With a CVSS score of 6.5, Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability: Ivanti Cloud Services Appliance (CSA) contains a SQL injection vulnerability in the admin web console in versions prior to 5.0.2, which can allow a remote attacker authenticated as administrator to run arbitrary SQL statements. As Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line, or later, of supported solution.

Advertisements

CVE-2024-9380

With a CVSS score of 7.8, Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability: Ivanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in the administrative console which can allow an authenticated attacker with application admin privileges to pass commands to the underlying OS. As Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line, or later, of supported solution.

CISA has set 30th October 2024 as deadline for the federal agencies to remediate the vulnerabilities.

Exit mobile version