HIGH

CVE-2024-9380

Ivanti Endpoint Manager Cloud Services Appliance 2024-10-08 CVSS v3.1
CVSS
7.2
KEV

Description

An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution.

Summary dbcve.org

Ivanti CSA versions before 5.0.2 contain an OS command injection vulnerability in the admin web console. A remote attacker with valid admin credentials can inject arbitrary OS commands through the web interface, leading to complete remote code execution on the affected appliance.

Mitigation

Upgrade Ivanti CSA to version 5.0.2 or later. If immediate patching is not possible, restrict administrative access to trusted IP addresses and monitor for unauthorized admin sessions.

Weakness (CWE)

CWE-77 Command Injection
CWE-78 OS Command Injection

EPSS Score

63.17%
Probability of exploitation in next 30 days
99.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE