Attackers Can Impersonate Any User in Ivanti ITSM Due to Certificate Validation Flaw
CVE-2024-7570

8.1HIGH

Key Information:

Vendor
Ivanti
Status
Vendor
CVE Published:
13 August 2024

Summary

The vulnerability allows improper certificate validation in Ivanti ITSM and Neurons for ITSM, enabling remote attackers positioned in a Man-in-the-Middle (MITM) scenario to forge tokens. This exploit could permit unauthorized access to the ITSM system as any user. Affected versions include Ivanti ITSM and Neurons for ITSM up to and including 2023.4, making it crucial for organizations utilizing these products to evaluate their security configurations and apply necessary patches to mitigate exposure to this vulnerability.

Affected Version(s)

ITSM 2023.4

ITSM 2023.4

ITSM 2023.4.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.