{"id":4223,"date":"2024-09-16T11:04:08","date_gmt":"2024-09-16T08:04:08","guid":{"rendered":"https:\/\/www.govcert.bg\/?p=4223"},"modified":"2024-09-16T13:11:56","modified_gmt":"2024-09-16T10:11:56","slug":"ivanti-%d0%bf%d1%83%d0%b1%d0%bb%d0%b8%d0%ba%d1%83%d0%b2%d0%b0-%d0%b0%d0%ba%d1%82%d1%83%d0%b0%d0%bb%d0%b8%d0%b7%d0%b0%d1%86%d0%b8%d1%8f-%d0%bd%d0%b0-%d0%b7%d0%b0%d1%89%d0%b8%d1%82%d0%b0%d1%82%d0%b0-3","status":"publish","type":"post","link":"https:\/\/www.govcert.bg\/en\/warnings\/ivanti-%d0%bf%d1%83%d0%b1%d0%bb%d0%b8%d0%ba%d1%83%d0%b2%d0%b0-%d0%b0%d0%ba%d1%82%d1%83%d0%b0%d0%bb%d0%b8%d0%b7%d0%b0%d1%86%d0%b8%d1%8f-%d0%bd%d0%b0-%d0%b7%d0%b0%d1%89%d0%b8%d1%82%d0%b0%d1%82%d0%b0-3\/","title":{"rendered":"Ivanti Releases Security Update for Cloud Services Appliance"},"content":{"rendered":"<p style=\"text-align: justify;\"><a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2024\/09\/13\/ivanti-releases-security-update-cloud-services-appliance\">Ivanti<\/a> has released a security update addressing an OS command injection vulnerability (CVE-2024-8190) affecting Ivanti Cloud Services Appliance (CSA) 4.6 (all versions before patch 519). A cyber threat actor could exploit this vulnerability to take control of an affected system.\u202f<\/p>\n<p style=\"text-align: justify;\">At this time, Ivanti has confirmed limited exploitation and urges its customers using the affected versions to upgrade to CSA version 5.0. Ivanti no longer supports CSA 4.6 (end-of-life).<\/p>\n<p style=\"text-align: justify;\"><strong>CERT Bulgaria<\/strong> recommends users and administrators review the guidance on eliminating OS command injections and the security advisory and apply the recommended updates:<\/p>\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.cisa.gov\/resources-tools\/resources\/secure-design-alert-eliminating-os-command-injection-vulnerabilities\">guidance on eliminating OS command injections<\/a><\/li>\n<li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-Ivanti-Cloud-Service-Appliance-CSA-CVE-2024-8190?language=en_US&amp;_gl=1*6frqvp*_gcl_au*MTIzMDUyNTU2My4xNzE4ODgyNzE0\">Ivanti security advisory<\/a><\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>Ivanti has released a security update addressing an OS command injection vulnerability (CVE-2024-8190) affecting Ivanti Cloud Services Appliance (CSA) 4.6 (all versions before patch 519). A cyber threat actor could exploit this vulnerability to take control of an affected system.\u202f <a title=\"Ivanti Releases Security Update for Cloud Services Appliance\" class=\"read-more\" href=\"https:\/\/www.govcert.bg\/en\/warnings\/ivanti-%d0%bf%d1%83%d0%b1%d0%bb%d0%b8%d0%ba%d1%83%d0%b2%d0%b0-%d0%b0%d0%ba%d1%82%d1%83%d0%b0%d0%bb%d0%b8%d0%b7%d0%b0%d1%86%d0%b8%d1%8f-%d0%bd%d0%b0-%d0%b7%d0%b0%d1%89%d0%b8%d1%82%d0%b0%d1%82%d0%b0-3\/\" aria-label=\"More on Ivanti \u043f\u0443\u0431\u043b\u0438\u043a\u0443\u0432\u0430 \u0430\u043a\u0442\u0443\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f \u043d\u0430 \u0437\u0430\u0449\u0438\u0442\u0430\u0442\u0430 \u0437\u0430 Cloud Services Appliance\">Read more<\/a><\/p>","protected":false},"author":6,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[44],"tags":[],"class_list":["post-4223","post","type-post","status-publish","format-standard","hentry","category-warnings"],"_links":{"self":[{"href":"https:\/\/www.govcert.bg\/en\/wp-json\/wp\/v2\/posts\/4223","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.govcert.bg\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.govcert.bg\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.govcert.bg\/en\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.govcert.bg\/en\/wp-json\/wp\/v2\/comments?post=4223"}],"version-history":[{"count":2,"href":"https:\/\/www.govcert.bg\/en\/wp-json\/wp\/v2\/posts\/4223\/revisions"}],"predecessor-version":[{"id":4225,"href":"https:\/\/www.govcert.bg\/en\/wp-json\/wp\/v2\/posts\/4223\/revisions\/4225"}],"wp:attachment":[{"href":"https:\/\/www.govcert.bg\/en\/wp-json\/wp\/v2\/media?parent=4223"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.govcert.bg\/en\/wp-json\/wp\/v2\/categories?post=4223"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.govcert.bg\/en\/wp-json\/wp\/v2\/tags?post=4223"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}