Target Industry
Indiscriminate, opportunistic targeting.
Overview
Assetnote has disclosed details relating to three ServiceNow vulnerabilities:
- CVE-2024-4879 (CVSS score 9.3): Improper Input Validation Vulnerability in ServiceNow Vancouver and Washington DC’s Now Platform releases
- CVE-2024-5217 (CVSS score 9.2): Incomplete List of Disallowed Inputs Vulnerability in ServiceNow Washington DC, Vancouver, and earlier Now Platform releases
- CVE-2024-5178 (CVSS score 6.9): Sensitive File Read Vulnerability in ServiceNow Washington DC, Vancouver, and Utah Now Platform releases.
Impact
Successful exploitation of CVE-2024-4879 or CVE-2024-5217 allows unauthenticated threat actors to remotely execute code within the context of the Now Platform.
Exploitation of CVE-2024-5178 allows administrative users to gain unauthorised access to sensitive files on the web application server.
Vulnerability Detection
ServiceNow has released patches pertaining to the security flaw for the respective product versions. As such, previous versions are vulnerable to the potential exploits.
Affected Products
Improper Input Validation Vulnerability (CVE-2024-4879):
- Utah
- Patch 10 before Hot Fix 3
- Patch 10a before Hot Fix 2
- Vancouver
- Patch 6 before Hot Fix 2
- Patch 7 before Hot Fix 3b
- Patch 8 before Hot Fix 4
- before Patch 9
- before Patch 10
- Washington DC
- Patch 1 before Hot Fix 2b
- Patch 2 before Hot Fix 2
- Patch 3 before Hot Fix 1
- before Patch 4
Incomplete List of Disallowed Inputs Vulnerability (CVE-2024-5217):
- Utah
- Patch 10 before Hot Fix 3
- Patch 10a before Hot Fix 2
- Patch 10b before Hot Fix 1
- Vancouver
- Patch 6 before Hot Fix 2
- Patch 7 before Hot Fix 3b
- Patch 8 before Hot Fix 4
- Patch 9 before Hot Fix 1
- before Patch 10
- Washington DC
- Patch 1 before Hot Fix 3b
- Patch 2 before Hot Fix 2
- Patch 3 before Hot Fix 2
- before Patch 4
- before Patch 5
Sensitive File Read Vulnerability (CVE-2024-5178):
- Utah:
- Patch 10 before Hot Fix 3
- Patch 10a before Hot Fix 2
- Patch 10b before Hot Fix 1
- Vancouver
- Patch 6 before Hot Fix 2
- Patch 7 before Hot Fix 3b
- Patch 8 before Hot Fix 4
- Patch 9 before Hot Fix 1
- before Patch 10
- Washington DC
- Patch 1 before Hot Fix 3b
- Patch 2 before Hot Fix 2
- Patch 3 before Hot Fix 2
- before Patch 4
Containment, Mitigations & Remediations
It is highly recommended that all organisations run the relevant patches as soon as possible.
Indicators of Compromise
No indicators of compromise (IoCs) are available currently.
Threat Landscape
ServiceNow is a comprehensive platform designed to facilitate business transformation. It offers a diverse range of modules, enabling its usage in various areas such as HR and employee management, workflow automation, and as a knowledge base. Notably, ServiceNow has emerged as a potentially appealing target due to its cloud-based nature, which often results in externally accessible instances. Moreover, the architectural design of ServiceNow implies that administrative access to an instance can lead to command execution on the MID Server, a proxy server situated within a company’s internal network.
Threat Group
No attribution to specific threat actors or groups has been identified at the time of writing.
Mitre Methodologies
Tactic:
- TA0002 – Execution
- TA0009 – Collection
- TA0010 – Exfiltration
Technique:
- T1648 – Serverless Execution
- T1555.006 – Credentials from Password Stores: Cloud Secrets Management Stores
Common Weakness Enumeration:
- CWE-1287 – Improper Validation of Specified Type of Input
- CWE-184 – Incomplete List of Disallowed Inputs
Further Information













