• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
alert: ivanti releases patch for critical vulnerability in endpoint manager

Alert: Ivanti Releases Patch for Critical Vulnerability in Endpoint Manager Solution

You are here: Home / General Cyber Security News / Alert: Ivanti Releases Patch for Critical Vulnerability in Endpoint Manager Solution
January 5, 2024

Ivanti has introduced security updates to handle a critical flaw impacting its Endpoint Supervisor (EPM) solution that, if productively exploited, could result in distant code execution (RCE) on vulnerable servers.

Tracked as CVE-2023-39336, the vulnerability has been rated 9.6 out of 10 on the CVSS scoring method. The shortcoming impacts EPM 2021 and EPM 2022 prior to SU5.

“If exploited, an attacker with accessibility to the inside network can leverage an unspecified SQL injection to execute arbitrary SQL queries and retrieve output devoid of the want for authentication,” Ivanti explained in an advisory.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Cybersecurity

“This can then make it possible for the attacker control around machines operating the EPM agent. When the main server is configured to use SQL convey, this may possibly guide to RCE on the main server.”

The disclosure arrived months just after the enterprise settled just about two dozen security flaws in its Avalanche enterprise mobile unit administration (MDM) solution.

Of the 21 issues, 13 are rated critical (CVSS scores: 9.8) and have been characterised as unauthenticated buffer overflows. They have been patched in Avalanche 6.4.2.

“An attacker sending specifically crafted details packets to the Cellular Product Server can bring about memory corruption which could outcome in a denial-of-support (DoS) or code execution,” Ivanti mentioned.

Cybersecurity

While there is no evidence that these aforementioned weaknesses have been exploited in the wild, condition-backed actors have, in the previous, exploited zero-working day flaws (CVE-2023-35078 and CVE-2023-35081) in Ivanti Endpoint Supervisor Cellular (EPMM) to infiltrate the networks of multiple Norwegian federal government companies.

A month afterwards, one more critical vulnerability in the Ivanti Sentry product (CVE-2023-38035, CVSS rating: 9.8) came under energetic exploitation as a zero-day.

Found this short article fascinating? Abide by us on Twitter  and LinkedIn to go through much more exclusive material we write-up.


Some areas of this write-up are sourced from:
thehackernews.com

Previous Post: «russian hackers had covert access to ukraine's telecom giant for Russian Hackers Had Covert Access to Ukraine’s Telecom Giant for Months
Next Post: Orange Spain Faces BGP Traffic Hijack After RIPE Account Hacked by Malware orange spain faces bgp traffic hijack after ripe account hacked»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Qilin Ransomware Adds “Call Lawyer” Feature to Pressure Victims for Larger Ransoms
  • Iran’s State TV Hijacked Mid-Broadcast Amid Geopolitical Tensions; $90M Stolen in Crypto Heist
  • 6 Steps to 24/7 In-House SOC Success
  • Massive 7.3 Tbps DDoS Attack Delivers 37.4 TB in 45 Seconds, Targeting Hosting Provider
  • 67 Trojanized GitHub Repositories Found in Campaign Targeting Gamers and Developers
  • New Android Malware Surge Hits Devices via Overlays, Virtualization Fraud and NFC Theft
  • BlueNoroff Deepfake Zoom Scam Hits Crypto Employee with MacOS Backdoor Malware
  • Secure Vibe Coding: The Complete New Guide
  • Uncover LOTS Attacks Hiding in Trusted Tools — Learn How in This Free Expert Session
  • Russian APT29 Exploits Gmail App Passwords to Bypass 2FA in Targeted Phishing Campaign

Copyright © TheCyberSecurity.News, All Rights Reserved.