PT-2024-6628 · Ivanti · Ivanti Cloud Services Appliance
Published
2024-09-19
·
Updated
2025-07-14
·
CVE-2024-8963
CVSS v2.0
9.7
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:P |
Name of the Vulnerable Software and Affected Versions:
Ivanti Cloud Services Appliance (CSA) versions before 4.6 Patch 519
Description:
The issue is a path traversal vulnerability in the Ivanti Cloud Services Appliance (CSA) that allows a remote unauthenticated attacker to access restricted functionality. This vulnerability is being actively exploited, and it enables unauthenticated attackers to bypass admin authentication and execute arbitrary commands. The estimated number of potentially affected devices worldwide is not specified, but the vulnerability has been added to the Cybersecurity and Infrastructure Security Agency’s (CISA’s) Known Exploited Vulnerabilities Catalog.
Recommendations:
To resolve the issue for Ivanti Cloud Services Appliance (CSA) versions before 4.6 Patch 519, patch to version 4.6 Patch 519 or upgrade to version 5.0. As a temporary workaround, consider restricting access to the vulnerable functionality until a patch is available. Additionally, ensure that all systems are up-to-date with the latest security patches, and monitor for any suspicious activity.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ivanti Cloud Services Appliance