Target Industry 

Indiscriminate, opportunistic targeting. 

Overview  

Assetnote has disclosed details relating to three ServiceNow vulnerabilities: 

  • CVE-2024-4879 (CVSS score 9.3): Improper Input Validation Vulnerability in ServiceNow Vancouver and Washington DC’s Now Platform releases 
  • CVE-2024-5217 (CVSS score 9.2): Incomplete List of Disallowed Inputs Vulnerability in ServiceNow Washington DC, Vancouver, and earlier Now Platform releases 
  • CVE-2024-5178 (CVSS score 6.9): Sensitive File Read Vulnerability in ServiceNow Washington DC, Vancouver, and Utah Now Platform releases. 

Impact  

Successful exploitation of CVE-2024-4879 or CVE-2024-5217 allows unauthenticated threat actors to remotely execute code within the context of the Now Platform. 

Exploitation of CVE-2024-5178 allows administrative users to gain unauthorised access to sensitive files on the web application server. 

Vulnerability Detection 

ServiceNow has released patches pertaining to the security flaw for the respective product versions. As such, previous versions are vulnerable to the potential exploits. 

Affected Products 

Improper Input Validation Vulnerability (CVE-2024-4879): 

  • Utah  
  • Patch 10 before Hot Fix 3 
  • Patch 10a before Hot Fix 2 
  • Vancouver  
  • Patch 6 before Hot Fix 2 
  • Patch 7 before Hot Fix 3b 
  • Patch 8 before Hot Fix 4 
  • before Patch 9 
  • before Patch 10 
  • Washington DC  
  • Patch 1 before Hot Fix 2b 
  • Patch 2 before Hot Fix 2 
  • Patch 3 before Hot Fix 1 
  • before Patch 4 

Incomplete List of Disallowed Inputs Vulnerability (CVE-2024-5217): 

  • Utah  
  • Patch 10 before Hot Fix 3 
  • Patch 10a before Hot Fix 2 
  • Patch 10b before Hot Fix 1  
  • Vancouver  
  • Patch 6 before Hot Fix 2 
  • Patch 7 before Hot Fix 3b 
  • Patch 8 before Hot Fix 4 
  • Patch 9 before Hot Fix 1 
  • before Patch 10 
  • Washington DC  
  • Patch 1 before Hot Fix 3b 
  • Patch 2 before Hot Fix 2 
  • Patch 3 before Hot Fix 2 
  • before Patch 4 
  • before Patch 5 

Sensitive File Read Vulnerability (CVE-2024-5178): 

  • Utah: 
  • Patch 10 before Hot Fix 3 
  • Patch 10a before Hot Fix 2 
  • Patch 10b before Hot Fix 1  
  • Vancouver  
  • Patch 6 before Hot Fix 2 
  • Patch 7 before Hot Fix 3b 
  • Patch 8 before Hot Fix 4 
  • Patch 9 before Hot Fix 1 
  • before Patch 10 
  • Washington DC  
  • Patch 1 before Hot Fix 3b 
  • Patch 2 before Hot Fix 2 
  • Patch 3 before Hot Fix 2 
  • before Patch 4 

Containment, Mitigations & Remediations 

It is highly recommended that all organisations run the relevant patches as soon as possible. 

Indicators of Compromise 

No indicators of compromise (IoCs) are available currently. 

Threat Landscape 

ServiceNow is a comprehensive platform designed to facilitate business transformation. It offers a diverse range of modules, enabling its usage in various areas such as HR and employee management, workflow automation, and as a knowledge base. Notably, ServiceNow has emerged as a potentially appealing target due to its cloud-based nature, which often results in externally accessible instances. Moreover, the architectural design of ServiceNow implies that administrative access to an instance can lead to command execution on the MID Server, a proxy server situated within a company’s internal network. 

Threat Group 

No attribution to specific threat actors or groups has been identified at the time of writing. 

Mitre Methodologies 

Tactic: 

Technique: 

  • T1648 – Serverless Execution 
  • T1555.006 – Credentials from Password Stores: Cloud Secrets Management Stores  

Common Weakness Enumeration: 

  • CWE-1287 – Improper Validation of Specified Type of Input 
  • CWE-184 – Incomplete List of Disallowed Inputs 

Further Information 

Assetnote 

 

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content