Article Details
Scrape Timestamp (UTC): 2024-04-04 04:47:43.474
Source: https://thehackernews.com/2024/04/ivanti-rushes-patches-for-4-new-flaw-in.html
Original Article Text
Click to Toggle View
Ivanti Rushes Patches for 4 New Flaw in Connect Secure and Policy Secure. Ivanti has released security updates to address four security flaws impacting Connect Secure and Policy Secure Gateways that could result in code execution and denial-of-service (DoS). The list of flaws is as follows - The company, which has been grappling with a steady stream of security flaws in its products since the start of the year, said it's not aware of "any customers being exploited by these vulnerabilities at the time of disclosure." Late last month, Ivanti shipped patches for critical shortcoming in its Standalone Sentry product (CVE-2023-41724, CVSS score: 9.6) that could permit an unauthenticated threat actor to execute arbitrary commands on the underlying operating system. It also resolved another critical flaw impacting on-premises versions of Neurons for ITSM (CVE-2023-46808, CVSS score: 9.9) that an authenticated remote attacker could abuse in order to perform arbitrary file writes and obtain code execution. In an open letter published on April 3, 2023, Ivanti's CEO Jeff Abbott said the company is taking a "close look" at its own posture and processes to meet the requirements of the current threat landscape. Abbott also said "events in recent months have been humbling" and that it's executing a plan that essentially changes its security operating model by adopting secure-by-design principles, sharing information with customers with complete transparency, and rearchitecting its engineering, security, and vulnerability management practices. "We are intensifying our internal scanning, manual exploitation and testing capabilities, engaging trusted third parties to augment our internal research and facilitating responsible disclosure of vulnerabilities with increased incentives around an enhanced bug bounty program," Abbott said. The Strategic Guide to Cloud Security Unlock practical steps to securing everything you build and run in the cloud. Goodbye, Atlassian Server. Goodbye… Backups? Protect your data on Atlassian Cloud from disaster with Rewind's daily backups and on-demand restores. How to Update and Automate Outdated Security Processes Download the eBook for step-by-step guidance on how to update your security processes as your business grows.
Daily Brief Summary
Ivanti has issued security updates addressing four vulnerabilities in Connect Secure and Policy Secure Gateways, which could lead to code execution and denial-of-service attacks.
No exploitation of these vulnerabilities has been reported at the time of the security update release.
The company had previously patched a critical vulnerability in its Standalone Sentry product that allowed for unauthenticated command execution.
Another critical flaw was fixed in the on-premises version of Neurons for ITSM, which could have enabled an authenticated remote attacker to write files and execute code.
Ivanti CEO Jeff Abbott publicly acknowledged the need to overhaul the company's security approach, including adoption of secure-by-design principles and transparency with customers.
Ivanti is enhancing its internal security mechanisms, utilizing third-party researchers, and expanding its bug bounty program to encourage responsible vulnerability disclosure.