CISA issued this year's first emergency directive ordering Federal Civilian Executive Branch (FCEB) agencies to immediately mitigate two Ivanti Connect Secure and Ivanti Policy Secure zero-day flaws in response to widespread and active exploitation by multiple threat actors. This is an expected development, given that vulnerable Ivanti appliances are now targeted in extensive attacks chaining the CVE-2023-46805 authentication bypass and the CVE-2024-21887 command injection vulnerabilities since December, and the vendor has yet to release security patches. When chained, the two Ivanti zero-days allow attackers to move laterally within a target's network, exfiltrate data, and establish persistent system access by deploying backdoors. "CISA has determined these conditions pose an unacceptable risk to Federal Civilian Executive Branch (FCEB) agencies and require emergency action," the cybersecurity agency said on Friday. "This determination is based on widespread exploitation of vulnerabilities by multiple threat actors, the prevalence of the affected products in the federal enterprise, the high potential for a compromise of agency information systems, the impact of a successful compromise, and the complexity of the proposed mitigations." As instructed by emergency directive ED 24-01, federal agencies now must promptly implement Ivanti's publicly disclosed mitigation measures to block attack attempts. The agencies are also required to use Ivanti's External Integrity Checker Tool...
CISA emergency directive: Mitigate Ivanti zero-days immediately
BleepingComputer
·Sergiu Gatlan
·Published Jan 19, 2024
·Updated
Affected Software
2 affected components
Ivanti Connect Secure
Ivanti Policy Secure
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses CISA's emergency directive for mitigating Ivanti zero-day vulnerabilities.
2
What security implications are discussed in the article?
The article highlights the urgent need to address critical zero-day flaws in Ivanti software to prevent potential exploitation.
3
What products are affected by the zero-day vulnerabilities?
The affected products are Ivanti Connect Secure and Ivanti Policy Secure.
4
Who is mandated to take action according to the directive?
Federal Civilian Executive Branch (FCEB) agencies are mandated to take immediate action.
5
What actions are recommended by CISA in response to the vulnerabilities?
CISA recommends immediate mitigation measures to address the Ivanti zero-day flaws.