H-ISAC TLP White: Threat Bulletin: Critical Flaw in Ivanti’s Cloud Services Appliance (CSA) is Being Exploited

The flaw is a patch traversal vulnerability affecting Ivanti’s Cloud Services Appliance (CSA) 4.6 devices. In the event of a successful attack, adversaries can bypass administrative control and gain access to sensitive data. The flaw's CVSS score is 9.4, highlighting the urgency of patching. The patches were rolled out as part of September CSA 4.6 Patch 519 updates

View the detailed bulletin below.

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

National Advisor for Cybersecurity and Risk, AHA

jriggi@aha.org

(O) +1 202 626 2272