Target Industry
Cloud Services Appliance (CSA) users, particularly those using Ivanti products.
Overview
Ivanti has released security updates to address three new zero-day vulnerabilities in its CSA. These vulnerabilities are actively being exploited in attacks. The flaws are being chained with another CSA zero-day that was patched in September.
Impact
The exploitation of these vulnerabilities allows attackers to gain unauthorised access and potentially compromise the affected systems. The vulnerabilities are critical as they can be exploited remotely without user interaction, making them highly dangerous.
Vulnerability Detection
Ivanti has identified and released patches for these vulnerabilities. Users are advised to apply these updates immediately to protect their systems from potential exploits. At the time of writing, the mechanism best used for identifying vulnerable products is the version number.
Exploitation
The vulnerabilities are actively being exploited in the wild, highlighting the urgency for users to update their systems. Admins and Security Operation Centres (SOCs) should review alerts from endpoint detection and response (EDR) or other security software as well as monitoring for the creation or modification of admin users.
Containment, Mitigations & Remediations
Ivanti has provided security updates to mitigate these vulnerabilities. Users should ensure their systems are updated to the latest versions to prevent exploitation. The flaw impacts CSA 5.0.1 and earlier. It is recommended that customers upgrade CSA appliances with version 5.0.2.
Threat Landscape
Given the critical nature of these vulnerabilities and the active exploitation, it is crucial for organisations using Ivanti CSA to remain vigilant and apply necessary security measures promptly.
Threat Group
No specific threat actors or groups have been attributed to these attacks at the time of writing.












