Attackers Can Impersonate Any User in Ivanti ITSM Due to Certificate Validation Flaw

CVE-2024-7570
8.1HIGH

Key Information

Vendor
Ivanti
Status
Itsm
Vendor
CVE Published:
13 August 2024

Summary

Improper certificate validation in Ivanti ITSM on-prem and Neurons for ITSM Versions 2023.4 and earlier allows a remote attacker in a MITM position to craft a token that would allow access to ITSM as any user.

Affected Version(s)

ITSM <= 2023.4

ITSM = 2023.4

ITSM >= 2023.4.0

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database
.