PT-2024-7354 · Ivanti · Ivanti Cloud Services Appliance

CVE-2024-9380

·

Published

2024-10-08

·

Updated

2026-08-31

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
The Ivanti Cloud Services Appliance (CSA) is affected by an OS command injection issue in its admin web console, prior to version 5.0.2. This allows a remote authenticated attacker with admin privileges to obtain remote code execution. The vulnerable versions are all Ivanti CSA versions before 5.0.2.
An exploit for this issue is available, and it is being actively exploited in the wild. To mitigate the risk, it is recommended to upgrade to version 5.0.2 or later.
Affected versions: Ivanti CSA before version 5.0.2.
#Ivanti #IvantiCSA #OSCommandInjection #RemoteCodeExecution #CyberSecurity #infosec #CloudSecurity

Fix

RCE

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-08716
CVE-2024-9380

Affected Products

Ivanti Cloud Services Appliance