PT-2024-7354 · Ivanti · Ivanti Cloud Services Appliance

Published

2024-10-08

·

Updated

2025-07-18

·

CVE-2024-9380

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Ivanti Cloud Services Appliance (CSA) versions prior to 5.0.2
Description: The issue is related to an OS command injection vulnerability in the admin web console of Ivanti CSA. This vulnerability allows a remote authenticated attacker with admin privileges to obtain remote code execution. The estimated number of potentially affected devices worldwide is not specified. However, it is mentioned that this type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks. There are reports of this issue being actively exploited in the wild.
Recommendations: For Ivanti Cloud Services Appliance (CSA) versions prior to 5.0.2, upgrade to version 5.0.2 or later to prevent authenticated admins from executing remote code. As a temporary workaround, consider restricting access to the admin web console to minimize the risk of exploitation.

Fix

RCE

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-08716
CVE-2024-9380

Affected Products

Ivanti Cloud Services Appliance