A Chinese threat actor is once again exploiting Ivanti remote access devices at large. If you had a nickel for every high-profile vulnerability affecting Ivanti appliances last year, you'd have a lot of nickels. There was the critical >authentication bypass in its Virtual Traffic Manager (vTM), the SQL injection bug in its Endpoint Manager, a trio affecting its Cloud Services Appliance (CSA), critical issues with its Standalone Sentry and Neurons for IT Service Management (ITSM), plus dozens more. It all started last January, when two serious vulnerabilities were discovered in Ivanti's Connect Secure (ICS) and Policy Secure gateways. By the time of disclosure, the vulnerabilities were already being exploited by a suspected Chinese-nexus threat actor, UNC5337, believed to be an entity of UNC5221. Now, one year and one secure-by-design pledge later, threat actors have returned to haunt Ivanti all over again, via a new critical vulnerability in ICS which also affects Policy Secure and Neurons for Zero Trust Access (ZTA) gateways. Ivanti has further warned of a second, slightly less severe bug that hasn't been observed in exploits yet. "Just because we're seeing these often doesn't necessarily mean that they're easy to pull off — it's a highly sophisticated group that is doing this," Arctic Wolf CISO Adam Marrè points out, in defense of the downtrodden IT vendor. "Engineering is not easy, and secure engineering is even more difficult. So even though you may be following the princ...
Threat Actors Exploit a Critical Ivanti RCE Bug, Again
Affected Software
Frequently Asked Questions
What is the main topic of this article?
The article discusses the exploitation of a critical remote code execution (RCE) vulnerability in Ivanti's remote access devices by a Chinese threat actor.
What security implications are discussed?
The article highlights the risks posed by ongoing exploitation of security vulnerabilities in Ivanti appliances, which can lead to unauthorized access and potential data breaches.
What products or software are affected?
The affected products include Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for Zero Trust Access.
Which versions of Ivanti products are vulnerable?
Vulnerable versions include Ivanti Connect Secure before 22.7R2.5, Ivanti Policy Secure before 22.7R1.2, and Ivanti Neurons for Zero Trust Access before 22.7R2.3.
What should users of Ivanti products do in response to this vulnerability?
Users of Ivanti products are advised to update their software to the latest versions to mitigate the risk of exploitation from this critical vulnerability.