HIGH

CVE-2024-9379

Ivanti Endpoint Manager Cloud Services Appliance 2024-10-08 CVSS v3.1
CVSS
7.2
KEV

Description

SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.

Summary dbcve.org

SQL injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to execute arbitrary SQL statements, potentially leading to data exfiltration or complete database compromise.

Mitigation

Upgrade Ivanti CSA to version 5.0.2 or later. Additionally, review admin account activity logs for signs of exploitation and consider rotating credentials given the prerequisite of admin-level access.

Weakness (CWE)

CWE-89 SQL Injection

EPSS Score

43.78%
Probability of exploitation in next 30 days
98.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE