CVE-2024-9380
Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 30 October 2024). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 63.17% probability · 99th percentile
- CISA KEV
- Listed 9 October 2024 · due 30 October 2024
- Weakness
- CWE-77, CWE-78
- Affected
- ivanti/endpoint manager cloud services appliance
- Source
- 3c1d8aa1-5a33-4ea4-8992-aadd6440af75
CISA notes
As Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line, or later, of supported solution. https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-CSA-Cloud-Services-Appliance-CVE-2024-9379-CVE-2024-9380-CVE-2024-9381 ; https://nvd.nist.gov/vuln/detail/CVE-2024-9380
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.