Threat Advisory

Trellix IPS Manager Critical Vulnerability Allows Remote Code Execution

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Researcher has patched a critical vulnerability CVE-2024-5671 in its IPS Manager, stemming from insecure deserialization in specific workflows. This flaw allows unauthenticated remote attackers to execute arbitrary code, posing a severe risk to network security. Rated with a CVSSv3 score of 9.8, the vulnerability could lead to unauthorized access, data theft, service disruption, and compromise of the entire managed network. Versions of Trellix IPS Manager prior to 11.1.x are affected. Enhancing monitoring capabilities to detect suspicious activities and restricting access to the IPS Restricting access to the Manager from sources that are not trusted is advisable as a temporary measure. This incident underscores the critical importance of timely updates and robust security practices to safeguard against such vulnerabilities, ensuring the confidentiality, integrity, and availability of network resources.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Researcher has patched a critical vulnerability CVE-2024-5671 in its IPS Manager, stemming from insecure deserialization in specific workflows. This flaw allows unauthenticated remote attackers to execute arbitrary code, posing a severe risk to network security. Rated with a CVSSv3 score of 9.8, the vulnerability could lead to unauthorized access, data theft, service disruption, and compromise of the entire managed network. Versions of Trellix IPS Manager prior to 11.1.x are affected. Enhancing monitoring capabilities to detect suspicious activities and restricting access to the IPS Restricting access to the Manager from sources that are not trusted is advisable as a temporary measure. This incident underscores the critical importance of timely updates and robust security practices to safeguard against such vulnerabilities, ensuring the confidentiality, integrity, and availability of network resources.[emaillocker id="1283"]

RECOMMENDATION:

We strongly recommend you update Trellix products from below reference:

REFERENCES:

The following reports contain further technical details:

https://cybersecuritynews.com/vulnerability-trellix-ips/

[/emaillocker]
crossmenu