PT-2024-7354 · Ivanti · Ivanti Cloud Services Appliance
CVE-2024-9380
·
Published
2024-10-08
·
Updated
2026-08-31
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
The Ivanti Cloud Services Appliance (CSA) is affected by an OS command injection issue in its admin web console, prior to version 5.0.2. This allows a remote authenticated attacker with admin privileges to obtain remote code execution. The vulnerable versions are all Ivanti CSA versions before 5.0.2.
An exploit for this issue is available, and it is being actively exploited in the wild. To mitigate the risk, it is recommended to upgrade to version 5.0.2 or later.
Affected versions: Ivanti CSA before version 5.0.2.
#Ivanti #IvantiCSA #OSCommandInjection #RemoteCodeExecution #CyberSecurity #infosec #CloudSecurity
Fix
RCE
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ivanti Cloud Services Appliance