CVE-2024-8190
Ivanti Cloud Services Appliance OS Command Injection Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 4 October 2024). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 88.53% probability · 100th percentile
- CISA KEV
- Listed 13 September 2024 · due 4 October 2024
- Weakness
- CWE-78
- Affected
- ivanti/cloud services appliance
- Source
- 3c1d8aa1-5a33-4ea4-8992-aadd6440af75
CISA notes
As Ivanti CSA has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line of supported solutions, as future vulnerabilities on the 4.6.x version of CSA are unlikely to receive future security updates. https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Service-Appliance-CSA-CVE-2024-8190; https://nvd.nist.gov/vuln/detail/CVE-2024-8190
References
- https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Service-Appliance-CSA-CVE-2024-8190Vendor Advisory
- https://www.cisa.gov/news-events/alerts/2024/09/13/ivanti-releases-security-update-cloud-services-applianceUS Government Resource
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-8190US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.