Raw vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HSummary
CVE-2024-7569 is a critical-severity Insertion of Sensitive Information Into Debugging Code (CWE-215) vulnerability in Ivanti Neurons For Itsm. Its CVSS base score is 9.6 (Critical).
Operationally, exploitation aligns with the MITRE ATT&CK technique Unsecured Credentials (T1552); ranked in the top 24% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to AC-3 (Access Enforcement) and AC-6 (Least Privilege) — see the control section below for these in your framework.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
CVE-2024-7569 is an information disclosure vulnerability affecting Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier. It stems from exposure of the OIDC client secret through debug information, as indicated by the associated CWEs covering insertion of sensitive information into externally accessible files and insecure storage of sensitive data.
An unauthenticated remote attacker can exploit the flaw over the network without requiring credentials or user interaction beyond a crafted request. Successful exploitation yields the OIDC client secret, enabling the attacker to achieve high-impact outcomes across confidentiality, integrity, and availability with a changed scope, consistent with the CVSS 9.6 rating.
The vendor has published a security advisory addressing the issue. The associated EPSS score has remained flat at 0.0747 with no material increase since disclosure.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2024-48468
Vulnerability Data
An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the OIDC client secret via debug information.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
—
—
- 3 hardening rules · 2 OS baselines
V13.4.2
Mitigating Controls (NIST 800-53 r5) AI
Enforces approved authorizations for logical access to stored information, directly stopping unauthorized read/write.
Requires protection of confidentiality/integrity for information at rest, directly addressing insecure storage.
Limits privileges so only authorized accesses to sensitive stored data are permitted.
Least functionality directly prohibits enabling unnecessary debug features that would expose the inserted sensitive data.
Developer testing and evaluation will discover debug code containing sensitive information before release.
Associates security attributes with information to support proper access decisions on storage.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Enforces least-privilege permissions and authorization reviews that limit read/write access to stored sensitive data.
Directly protects data-at-rest confidentiality via encryption or access controls that prevent unauthorized reads.
Secure SDLC practices directly prevent developers from embedding sensitive information inside debugging statements or code paths.
Explicitly calls for removing confidential data from processes, logs, and memory dumps that debug code commonly exposes.
Hardened configuration baselines and deployment checks can ensure debug features and associated data are disabled in production.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing in development catches debug statements and sensitive data leaks.
Separation of environments reduces accidental exposure of debug builds to production.
Secure SDLC mandates removal of debug code and sensitive data before release.
Secure coding standards explicitly prohibit embedding secrets or debug statements.
Secure reuse and disposal procedures, including cryptographic wiping and physical destruction, stop the insecure storage of sensitive data on media that may later be accessed by unauthorized actors.
Mandating secure disposal techniques stops the insecure retention of sensitive information on storage media that leaves organizational control.
Hardening callouts derived
Configuration rules from DISA STIG baselines that bear on weaknesses of the type cited by this CVE. Each rule is shown with the relationship its mapping actually records, against the CWE it was authored against. Derived via CVE→CWE over `controls_xwalks` (authoritative rows only; rows rated `none` are excluded).
Windows Server 2016 (2 rules)
- V-224973 The Active Directory Domain Controllers Organizational Unit (OU) object must have the proper access control permissions. prevents CWE-922
- V-224974 Domain-created Active Directory Organizational Unit (OU) objects must have proper access control permissions. prevents CWE-922
Windows Server 2019 (1 rule)
- V-205743 Windows Server 2019 organization created Active Directory Organizational Unit (OU) objects must have proper access control permissions. prevents CWE-922