Ivanti Cloud Services Appliance Zero-Day Attack

Released: Jan 24, 2025


Critical Severity

Ivanti Vendor


Suspected Nation-State Adversary Targets Ivanti CSA

Threat actors chained and exploited multiple zero-day vulnerabilities affecting Ivanti CSA (Cloud Services Appliance). If successful, this could lead an attacker to gain admin access, obtain credentials, bypass security measures, run arbitrary SQL commands, and execute code remotely. Learn More »

Common Vulnerabilities and Exposures






Background

In an incident response engagement during September 2024, FortiGuard Incident Response (FGIR) services discovered a campaign targeting Ivanti Cloud Services Appliance (CSA) for initial access and released a detailed Threat Blog. To read more, visit: https://www.fortinet.com/blog/threat-research/burning-zero-days-suspected-nation-state-adversary-targets-ivanti-csa

According to a new report released by CISA on 22 January 2025, in response to exploitation activities relating to Ivanti Cloud Service Appliances (CSA): CVE-2024-8963, CVE-2024-9379, CVE-2024-8190 and CVE-2024-9380, threat actors chained the listed vulnerabilities to gain initial access, conduct remote code execution (RCE), obtain credentials, and implant webshells on victim networks.

Ivanti has available updates for Ivanti CSA (Cloud Services Appliance) which addresses these vulnerabilities. FortiGuard recommends users apply the vendor's fixes as mentioned in the advisory and validate your security controls. (See the References section for the link to the patch release)

Latest Development

Recent news and incidents related to cybersecurity threats encompassing various events such as data breaches, cyber-attacks, security incidents, and vulnerabilities discovered.


Please note: Ivanti recently disclosed two vulnerabilities (CVE-2025-0282, CVE-2025-0283 affecting, Ivanti Connect Secure, Policy Secure & ZTA Gateways - To read more, see the related FortiGuard Threat Signal posted at https://www.fortiguard.com/threat-signal-report/5612

FortiGuard Cybersecurity Framework

Mitigate security threats and vulnerabilities by leveraging the range of FortiGuard Services.


PROTECT
  • Lure

  • Decoy VM

  • AV

  • AV (Pre-filter)

  • Behavior Detection

  • IPS

DETECT
  • IOC

  • Outbreak Detection

  • Threat Hunting

  • Cloud Threat Detection

RESPOND
  • Automated Response

  • Assisted Response Services

RECOVER
  • NOC/SOC Training

  • End-User Training

IDENTIFY
  • Attack Surface Monitoring (Inside & Outside)

  • Attack Surface Hardening

Threat Intelligence

Information gathered from analyzing ongoing cybersecurity events including threat actors, their tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), malware and related vulnerabilities.