cloud

Multiple Attacks Force CISA to Order US Agencies to Upgrade or Remove End-of-Life Ivanti Appliance – Slashdot

Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

Posted by EditorDavid from the high-severity-vulnerabilities dept.

On Tuesday Ivanti issued a “high severity vulnerability” announcement for version 4.6 of its Cloud Service Appliance (or CSA). “Successful exploitation could lead to unauthorized access to the device running the CSA.” And Friday that announcement got an update: Ivanti “has confirmed exploitation of this vulnerability in the wild.”

While Ivanti released a security update, they warned that “with the end-of-life status this is the last fix that Ivanti will backport for this version. Customers must upgrade to Ivanti CSA 5.0 for continued support.”

This prompted a response from CISA (the Cybersecurity and Infrastructure Security Agency, part of the U.S. Department of Homeland Security). The noted that Ivanti is urging customers to upgrade to version 5.0, as “Ivanti no longer supports CSA 4.6 (end-of-life).” But in addition, CISA “ordered all federal civilian agencies to remove CSA 4.6. from service or upgrade to the 5.0. by October 4,” reports the Record: Ivanti said users will know they are impacted by exploitation of the bug by looking to see if there are modified or newly added administrative users. They also urged customers to check security alerts if they have certain security tools involved.

The issue arose one day after another Ivanti bug caused alarm among defenders. The company pledged a security overhaul in April after a cascade of headline-grabbing nation-state attacks broke through the systems of government agencies in the U.S. and Europe using vulnerabilities in Ivanti products.

The wages of sin are unreported.

Working…

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Back to top button

Adblock Detected

Block the adblockers from browsing the site, till they turn off the Ad Blocker.