HIGH
CVE-2024-9380
CVSS
7.2
KEV
Description
An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution.
Summary dbcve.org
Ivanti CSA versions before 5.0.2 contain an OS command injection vulnerability in the admin web console. A remote attacker with valid admin credentials can inject arbitrary OS commands through the web interface, leading to complete remote code execution on the affected appliance.
Mitigation
Upgrade Ivanti CSA to version 5.0.2 or later. If immediate patching is not possible, restrict administrative access to trusted IP addresses and monitor for unauthorized admin sessions.
Weakness (CWE)
CWE-77
Command Injection
CWE-78
OS Command Injection
EPSS Score
63.17%
Probability of exploitation in next 30 days
99.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.