"Exploiting this flaw could have serious consequences, such as data breaches, disruption of business operations, and further compromise of internal systems," Eric Schwake, director of cybersecurity strategy at Salt Security, wrote in an emailed statement. One of the latest vulnerabilities that the Cybersecurity and Infrastructure Security Agency has added to the Known Exploited Vulnerabilities Catalog is CVE-2024-29824, found in the Ivanti Endpoint Manager. "Organizations using Ivanti EPM should prioritize patching their systems immediately and conduct thorough security assessments to detect and mitigate potential compromise. 1, Ivanti updated its security advisory to reflect that the vulnerability had been exploited in the wild. "At the time of this update, we are aware of a limited number of customers who have been exploited," according to Ivanti's advisory. Ivanti released security updates to patch this flaw in May, alongside several other bugs found in EPM's core server.
This Cyber News was published on www.darkreading.com. Publication date: Thu, 03 Oct 2024 21:20:32 +0000