HIGH

CVE-2024-8190

Ivanti Cloud Services Appliance 2024-09-10 CVSS v3.1
CVSS
7.2
KEV

Description

An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.

Summary dbcve.org

OS command injection vulnerability in Ivanti Cloud Services Appliance allows authenticated administrators to inject and execute arbitrary OS commands, leading to full remote code execution on the affected appliance.

Mitigation

Upgrade to a patched version beyond 4.6 Patch 518 and apply latest security updates. Restrict admin access to trusted personnel and implement network segmentation to limit exposure.

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

88.54%
Probability of exploitation in next 30 days
99.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE