CVE-2021-44529
Description
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
Summary dbcve.org
A code injection vulnerability exists in the Ivanti EPM Cloud Services Appliance (CSA) that enables an unauthenticated remote attacker to execute arbitrary code on the appliance. The executed code runs with the limited 'nobody' account, which still represents a critical risk on a network-administrative appliance exposed for cloud services. Exploitation requires no credentials, which combined with the critical CVSS 9.8 score makes unauthenticated remote code execution a high-impact scenario requiring immediate remediation via the vendor's published fix.
Mitigation
Apply the vendor-supplied security patch for Ivanti EPM Cloud Services Appliance (CSA) addressing CVE-2021-44529 without delay, following Ivanti's official advisory and upgrade guidance. Restrict network exposure of the CSA management interface to trusted administrators only until the patch is applied, and verify post-upgrade that the appliance is no longer vulnerable.