PT-2024-6628 · Ivanti · Ivanti Cloud Services Appliance
CVE-2024-8963
·
Published
2024-09-19
·
Updated
2026-08-31
CVSS v2.0
9.7
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:P |
The vulnerable software is Ivanti's Cloud Services Appliance (CSA), specifically versions before 4.6 Patch 519. This path traversal issue allows a remote unauthenticated attacker to access restricted functionality. The flaw is being actively exploited, and it is recommended to patch to version 4.6 Patch 519 or upgrade to version 5.0 to stay protected. An exploit for this issue is available, and a limited number of customers have been exploited by this vulnerability. The vulnerability can be exploited by unauthenticated attackers to bypass admin authentication and execute arbitrary commands.
Vulnerable versions: Ivanti Cloud Services Appliance (CSA) before 4.6 Patch 519.
#Ivanti #CloudServicesAppliance #PathTraversal #Cybersecurity #VulnerabilityAlert #PatchNow #InfoSec #CyberSecurityAwareness #DataBreach
Fix
DoS
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ivanti Cloud Services Appliance