Security Snippets: Ivanti faced with a third critical vulnerability according to CISA

Hogan Lovells
Contact

Hogan Lovells[co-author: Rachel Dalton]

CISA has added a new Ivanti vulnerability to its known exploited vulnerability catalogue. This vulnerability can be paired with other recently-reported vulnerabilities to permit threat actors to write malicious web shell files to the appliance.


CISA added a third vulnerability in Ivanti’s Endpoint Manager Mobile (EPMM) to its known exploited vulnerabilities (KEV) catalogue. This vulnerability is tracked as CVE-2023-35082 and has received a severity score of 9.8 out of 10—it can be used as a patch bypass for an additional Ivanti vulnerability that was used in against the Norwegian government in April 2023.

Previous Ivanti vulnerabilities have been addressed in Hogan Lovells thought leadership. Ivanti released a patch for the first vulnerability on January 22 and plans to release a patch for the second vulnerability on February 19. Ivanti is aware of CVE-2023-35082 and has encouraged customers to update their technology for the greatest possible protection.

CISA recommends federal agencies to apply patches to all existing vulnerabilities by February 8, 2024.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Hogan Lovells | Attorney Advertising

Written by:

Hogan Lovells
Contact
more
less

Hogan Lovells on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide