PT-2024-8347 · Ivanti · Ivanti Itsm+1
Published
2024-08-06
·
Updated
2025-05-13
·
CVE-2024-7570
CVSS v3.1
8.3
High
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier
Description
The issue is related to improper certificate validation, which can be exploited by a remote attacker in a MITM position to create a token that would allow access to ITSM as any user. This can pose a serious threat to user data. The vulnerability is associated with the incorrect implementation of the OpenID Connect protocol.
Recommendations
For Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier, update to a secure version to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of ITSM to minimize the risk of exploitation. Additionally, review and strengthen security measures related to certificate validation and MITM attack prevention.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ivanti Itsm
Neurons For Itsm