Attackers Can Impersonate Any User in Ivanti ITSM Due to Certificate Validation Flaw
CVE-2024-7570
What is CVE-2024-7570?
The vulnerability allows improper certificate validation in Ivanti ITSM and Neurons for ITSM, enabling remote attackers positioned in a Man-in-the-Middle (MITM) scenario to forge tokens. This exploit could permit unauthorized access to the ITSM system as any user. Affected versions include Ivanti ITSM and Neurons for ITSM up to and including 2023.4, making it crucial for organizations utilizing these products to evaluate their security configurations and apply necessary patches to mitigate exposure to this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ITSM 2023.4
ITSM 2023.4
ITSM 2023.4.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved