Ivanti Security Updates – 21 March 2024

Ivanti has released security updates to fix two critical vulnerabilities across Ivanti Neurons for ITSM and Ivanti Standalone Sentry.

The addressed vulnerabilities could allow the remote attacker to execute arbitrary code, and gain access to the affected systems.

The addressed vulnerabilities:

1. Ivanti Neurons for ITSM Code Execution Vulnerability (CVE-2023-46808):

  • CVSS: 9.9
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Gain Access

2. Ivanti Standalone Sentry Code Execution Vulnerability (CVE-2023-41724):

  • CVSS: 9.6
  • Attack Vector: Adjacent Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities
  • CVE-2023-46808
  • CVE-2023-41724
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Ivanti Security Advisory

References