Security News > 2023 > July > CISA warns govt agencies to patch Ivanti bug exploited in attacks

CISA warns govt agencies to patch Ivanti bug exploited in attacks
2023-07-25 20:41

Ivanti has also confirmed that the bug is actively exploited in attacks and warned customers that it's critical to "Immediately take action" to ensure their systems are fully protected.

U.S. Federal Civilian Executive Branch Agencies have a three-week deadline, until August 15th, to secure their devices against attacks targeting the CVE-2023-35078 flaw, which was added to CISA's list of Known Exploited Vulnerabilities on Tuesday.

The U.S. cybersecurity agency also gave federal agencies three weeks to patch their Adobe ColdFusion servers against two critical security flaws exploited in attacks, one of them as a zero-day.

Ivanti patches MobileIron zero-day bug exploited in attacks.

CISA warns govt agencies to patch Adobe ColdFusion servers.

CISA orders agencies to patch iPhone bugs abused in spyware attacks.


News URL

https://www.bleepingcomputer.com/news/security/cisa-warns-govt-agencies-to-patch-ivanti-bug-exploited-in-attacks/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2023-07-25 CVE-2023-35078 Improper Authentication vulnerability in Ivanti Endpoint Manager Mobile
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.
network
low complexity
ivanti CWE-287
critical
9.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Ivanti 26 9 64 99 58 230