CVE-2024-7570

HIGH

Ivanti Neurons for ITSM 2023.4 and earlier - Improper Certificate Validation

Title source: llm
STIX 2.1

Description

Improper certificate validation in Ivanti ITSM on-prem and Neurons for ITSM Versions 2023.4 and earlier allows a remote attacker in a MITM position to craft a token that would allow access to ITSM as any user.

Scores

CVSS v3 8.3
EPSS 0.0183
EPSS Percentile 83.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-295
Status published
Products (3)
ivanti/neurons_for_itsm 2023.2
ivanti/neurons_for_itsm 2023.3
ivanti/neurons_for_itsm 2023.4
Published Aug 13, 2024
Tracked Since Feb 18, 2026