The Cybersecurity and Infrastructure Security Agency (CISA) has announced the addition of a new vulnerability to its Known Exploited Vulnerabilities Catalog. As cyber threats continue to evolve, CISA remains committed to updating its catalog with vulnerabilities that meet specific risk and exploitation criteria. This latest addition to the Known Exploited Vulnerabilities Catalog is part of an ongoing effort under Binding Operational Directive (BOD) 22-01. “An unrestricted file upload vulnerability in web component of Ivanti Avalanche before 6.4.x allows an authenticated, privileged user to execute arbitrary commands as SYSTEM.” Ianvti added. This directive mandates that Federal Civilian Executive Branch (FCEB) agencies address known vulnerabilities by specified deadlines to safeguard their networks against active threats. Organizations are encouraged to integrate these updates into their regular vulnerability management practices to maintain robust defenses against potential cyber threats. The CVE-2024-29824 vulnerability in Ivanti EPM represents a serious risk due to its potential for exploitation through SQL Injection attacks. While BOD 22-01 explicitly targets FCEB agencies, CISA strongly advises all organizations to prioritize the timely remediation of vulnerabilities listed in the catalog. The newly identified vulnerability, CVE-2024-29824, affects Ivanti Endpoint Manager (EPM) and involves an SQL Injection flaw that malicious actors actively exploit. The catalog serves as a dynamic list of Common Vulnerabilities and Exposures (CVEs) that pose significant risks to federal enterprises. Ivanti is a U.S.-based IT software company that provides enterprise software solutions for managing IT assets, IT service management, and cybersecurity. Horizon3.ai researchers published a detailed analysis of the CVE-2024-29824 vulnerability with technical insights and mitigation strategies. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security. Get Latest Hacker News & Cyber Security Newsletters update Daily.
This Cyber News was published on cybersecuritynews.com. Publication date: Thu, 03 Oct 2024 06:30:37 +0000