AI
AI

CISA Alerts on Active Exploitation of Ivanti EPM Vulnerabilities

Photo credit: www.csoonline.com

Credential Coercion

According to cybersecurity expert Hanley, vulnerabilities related to credential coercion could pose serious risks. These flaws may facilitate unauthorized attackers in exploiting the Ivanti EPM machine account credentials, potentially enabling NTLM relay attacks that could lead to server breaches.

Ivanti EPM is a comprehensive asset monitoring and management platform designed for businesses, capable of overseeing a range of desktop and mobile devices. The core server component is built on the .NET framework and provides various API endpoints for its operations.

Hanley identified that several unauthenticated API endpoints lacked adequate input validation, allowing for the possibility of injecting UNC absolute paths into multiple methods. Specifically, these methods—GetHashForFile, GetHashForSingleFile, GetHashForWildcard, and GetHashForWildcardRecursive—are intended to generate file hashes within designated directories.

Source
www.csoonline.com

Related by category

Broadcom-Supported SAN Devices Vulnerable to Code Injection Attacks Due to Critical Fabric OS Flaw

Photo credit: www.csoonline.com Critical Vulnerability Found in Broadcom’s Brocade Fabric...

Cyberattack on berlin.de | CSO Online

Photo credit: www.csoonline.com Cyberangriff auf Berlins Info- und Serviceportal berlin.de Ende...

The Rising Tide of Intrusions: Increased Stolen Credentials and Perimeter Exploits Amid Declining Phishing Attacks

Photo credit: www.csoonline.com The landscape of cybersecurity continues to evolve,...

Latest news

Life in Iraq’s “Restricted Area”

Photo credit: www.bbc.com Life Under Threat in Iraqi Kurdistan: The...

Waymo and Toyota Join Forces to Integrate Self-Driving Technology into Personal Vehicles

Photo credit: www.cnbc.com A Waymo self-driving vehicle, featuring a driver,...

White House Budget Office “Unresponsive” to Investigations Regarding Frozen Funds, GAO Report Reveals

Photo credit: thehill.com GAO Chief Highlights Challenges in Accessing Information...

Breaking news