Ivanti Patches Critical Vulnerabilities in Neurons for ITSM, Virtual Traffic Manager

August 14, 2024 at 06:57AM Ivanti announced patches for eight vulnerabilities in Neurons for ITSM, Avalanche, and Virtual Traffic Manager, including two critical-severity flaws. The patches address security defects, such as information disclosure and improper certificate validation, and are available for download. Ivanti recommends customers upgrade to the patched versions to mitigate potential risks. Based … Read more

Ivanti Patches Critical Remote Code Execution Flaws in Endpoint Manager

May 23, 2024 at 05:39AM Ivanti has released fixes for multiple critical security flaws in Endpoint Manager (EPM), addressing SQL injection vulnerabilities and high-severity security flaws in other products. Additionally, a critical flaw in the open-source Genie federated Big Data orchestration and execution engine has been disclosed, posing a risk for remote code execution. The … Read more

Ivanti Releases Fixes for More Than 2 Dozen Vulnerabilities

April 17, 2024 at 02:38PM Ivanti has released 27 fixes for vulnerabilities in its 2024 first-quarter release. None are actively exploited. Users are advised to download the Avalanche installer and update to version 6.4.3 to apply the fixes. The vulnerabilities have CVSS scores ranging from 4.3 to 9.8. Ivanti recommends users keep their MSSQL database … Read more

Ivanti warns of critical flaws in its Avalanche MDM solution

April 16, 2024 at 03:57PM Ivanti released security updates to address 27 vulnerabilities in its Avalanche mobile device management (MDM) solution, including critical heap overflows enabling remote command execution. Additionally, 25 medium and high-severity bugs were patched, fixing issues such as denial-of-service attacks and remote code execution. Users are advised to update to the latest … Read more

Ivanti Patches Dozen Critical Vulnerabilities in Avalanche MDM Product

December 21, 2023 at 07:33AM Ivanti has released Avalanche 6.4.2 to patch 20 vulnerabilities in its enterprise mobile device management product. The flaws, including critical ones, can be exploited for remote code execution and denial-of-service attacks. Customers are urged to install the patches promptly due to the potential targeting of Ivanti product vulnerabilities by threat … Read more

Ivanti releases patches for 13 critical Avalanche RCE flaws

December 20, 2023 at 01:10PM Ivanti released security updates fixing 13 critical vulnerabilities in their Avalanche enterprise mobile device management (MDM) solution. The flaws relate to buffer overflows. Unauthenticated attackers could exploit them for remote code execution. All issues were resolved in Avalanche v6.4.2.313. CISA and NCSC-NO have expressed concern about potential widespread exploitation in … Read more