CVE-2024-9379
Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 30 October 2024). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 43.78% probability · 99th percentile
- CISA KEV
- Listed 9 October 2024 · due 30 October 2024
- Weakness
- CWE-89
- Affected
- ivanti/endpoint manager cloud services appliance
- Source
- 3c1d8aa1-5a33-4ea4-8992-aadd6440af75
CISA notes
As Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line, or later, of supported solution. https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-CSA-Cloud-Services-Appliance-CVE-2024-9379-CVE-2024-9380-CVE-2024-9381 ; https://nvd.nist.gov/vuln/detail/CVE-2024-9379
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.