{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aivantisecure_access_client22.7r3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ivanti:neurons_for_itsm:2023.2:*:*:*:*:*:*:*","cpe:2.3:a:ivanti:neurons_for_itsm:2023.3:*:*:*:*:*:*:*","cpe:2.3:a:ivanti:neurons_for_itsm:2023.4:*:*:*:*:*:*:*","cpe:2.3:a:ivanti:secure_access_client:*:*:*:*:*:*:*:*","cpe:2.3:a:ivanti:secure_access_client:22.7:-:*:*:*:*:*:*","cpe:2.3:a:ivanti:secure_access_client:22.7:r1:*:*:*:*:*:*","cpe:2.3:a:ivanti:secure_access_client:22.7:r1.1:*:*:*:*:*:*","cpe:2.3:a:ivanti:secure_access_client:22.7:r2:*:*:*:*:*:*","cpe:2.3:a:ivanti:secure_access_client:22.7:r3:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.6,"id":"CVE-2024-7569"},{"cvss":8.3,"id":"CVE-2024-7570"},{"cvss":7.8,"id":"CVE-2024-7571"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Neurons for ITSM (\u003c= 2023.4)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","remote-code-execution","ivanti"],"_cs_type":"advisory","_cs_vendors":["Ivanti"],"content_html":"\u003cp\u003eIvanti has disclosed multiple vulnerabilities affecting Ivanti Neurons for ITSM. These flaws include CVE-2024-7569, CVE-2024-7570, and CVE-2024-7571. These vulnerabilities reside within the ITSM application framework and, when successfully exploited, allow a remote, unauthenticated attacker to execute arbitrary code within the context of the application. Given the nature of ITSM platforms, which often run with elevated service account privileges, successful exploitation could lead to full application compromise, lateral movement within the network, and exfiltration of sensitive configuration or identity data stored within the ITSM database. Defenders should treat these vulnerabilities as high-priority targets for patching due to the potential for unauthenticated access.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities allows an attacker to achieve remote code execution on the affected server. This could lead to a complete compromise of the Ivanti Neurons for ITSM instance, unauthorized access to sensitive service desk data, potential pivot points into the internal network, and the deployment of persistent backdoors.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching all internet-facing and internal instances of Ivanti Neurons for ITSM to the latest vendor-supplied version addressing CVE-2024-7569, CVE-2024-7570, and CVE-2024-7571. Ensure that service accounts used by the ITSM platform follow the principle of least privilege to minimize the impact of a potential RCE event. Restrict network access to the Ivanti Neurons for ITSM interface to authorized internal subnets via firewalls until updates can be applied.\u003c/p\u003e\n","date_modified":"2026-09-09T12:49:10Z","date_published":"2026-09-09T12:49:10Z","id":"https://feed.craftedsignal.io/briefs/2026-09-ivanti-it-rce/","summary":"Multiple vulnerabilities in Ivanti Neurons for ITSM (CVE-2024-7569, CVE-2024-7570, CVE-2024-7571) allow a remote unauthenticated attacker to achieve remote code execution.","title":"Multiple Remote Code Execution Vulnerabilities in Ivanti Neurons for ITSM","url":"https://feed.craftedsignal.io/briefs/2026-09-ivanti-it-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:ivanti:secure_access_client:22.7:r3:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}