Ivanti Product Security Update Advisory

Overview

 

Ivanti has made available an update that addresses a vulnerability in their product. users of affected versions are advised to update to the latest version.

 

Affected Products

 

CVE-2023-41724

  • Ivanti Standalone Sentry 9.17.0 or below
  • Ivanti Standalone Sentry 9.18.0 or below
  • Ivanti Standalone Sentry 9.19.0 or below

 

CVE-2023-46808

  • Ivanti Neurons (ITSM) 2023.3
  • Ivanti Neurons (ITSM) 2023.2
  • Ivanti Neurons (ITSM) 2023.1

 

Resolved Vulnerabilities

 

Remote code execution vulnerability in Ivanti Standalone Sentry (CVE-2023-41724) [1]
Remote file write vulnerability in an authenticated environment in Ivanti Neurons (ITSM) (CVE-2023-46808) [2]

 

Vulnerability Patches

 

vulnerability Patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

CVE-2023-41724

  • Ivanti Standalone Sentry versions 9.17.1, 9.18.1, and 9.19.1

 

CVE-2023-46808

  • Apply the latest patch for Ivanti Neurons (ITSM) 2023.X

 

Referenced Sites

 

[1] KB-CVE-2023-41724 (Remote Code Execution) for Ivanti Standalone Sentry

https://forums.ivanti.com/s/article/KB-CVE-2023-41724-Remote-Code-Execution-for-Ivanti-Standalone-Sentry?language=en_US

[2] CVE-2023-46808 (Authenticated Remote File Write) for Ivanti Neurons for ITSM

https://forums.ivanti.com/s/article/CVE-2023-46808-Authenticated-Remote-File-Write-for-Ivanti-Neurons-for-ITSM?language=en_US