PT-2024-6628 · Ivanti · Ivanti Cloud Services Appliance

CVE-2024-8963

·

Published

2024-09-19

·

Updated

2026-08-31

CVSS v2.0

9.7

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:P
The vulnerable software is Ivanti's Cloud Services Appliance (CSA), specifically versions before 4.6 Patch 519. This path traversal issue allows a remote unauthenticated attacker to access restricted functionality. The flaw is being actively exploited, and it is recommended to patch to version 4.6 Patch 519 or upgrade to version 5.0 to stay protected. An exploit for this issue is available, and a limited number of customers have been exploited by this vulnerability. The vulnerability can be exploited by unauthenticated attackers to bypass admin authentication and execute arbitrary commands.
Vulnerable versions: Ivanti Cloud Services Appliance (CSA) before 4.6 Patch 519.
#Ivanti #CloudServicesAppliance #PathTraversal #Cybersecurity #VulnerabilityAlert #PatchNow #InfoSec #CyberSecurityAwareness #DataBreach

Fix

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-07787
CVE-2024-8963

Affected Products

Ivanti Cloud Services Appliance