On 22 January, Ivanti published an advisory stating that they discovered two new, high-severity vulnerabilities after researching previously reported vulnerabilities affecting Ivanti Connect Secure, Ivanti Policy Secure and ZTA gateways.
Ivanti provides enterprise solutions, including patch management and IT security solutions to over 40,000 customers worldwide.
While there is no evidence of any customers being impacted by CVE-2024-21888, Ivanti has acknowledged CVE-2024-21893 has impacted some customers in targeted instances.
All NodeZero™️ users can run an autonomous pentest to determine if their systems are vulnerable to the Ivanti vulnerability.
We also recommend running a follow-on pentest to verify that any remediation steps taken, such as patching, are effective.
This is a Security Bloggers Network syndicated blog from Horizon3.
This Cyber News was published on securityboulevard.com. Publication date: Tue, 06 Feb 2024 00:13:06 +0000