HIGH
CVE-2024-8190
CVSS
7.2
KEV
Description
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.
Summary dbcve.org
OS command injection vulnerability in Ivanti Cloud Services Appliance allows authenticated administrators to inject and execute arbitrary OS commands, leading to full remote code execution on the affected appliance.
Mitigation
Upgrade to a patched version beyond 4.6 Patch 518 and apply latest security updates. Restrict admin access to trusted personnel and implement network segmentation to limit exposure.
Weakness (CWE)
CWE-78
OS Command Injection
EPSS Score
88.54%
Probability of exploitation in next 30 days
99.8th percentile
References
https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Service-Appliance-CSA-CVE-2024-8190
Vendor Advisory
https://www.cisa.gov/news-events/alerts/2024/09/13/ivanti-releases-security-update-cloud-services-appliance
US Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-8190
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.