HIGH
CVE-2024-9379
CVSS
7.2
KEV
Description
SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
Summary dbcve.org
SQL injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to execute arbitrary SQL statements, potentially leading to data exfiltration or complete database compromise.
Mitigation
Upgrade Ivanti CSA to version 5.0.2 or later. Additionally, review admin account activity logs for signs of exploitation and consider rotating credentials given the prerequisite of admin-level access.
Weakness (CWE)
CWE-89
SQL Injection
EPSS Score
43.78%
Probability of exploitation in next 30 days
98.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.