PT-2024-7355 · Ivanti · Ivanti Csa
Published
2024-10-08
·
Updated
2025-02-11
·
CVE-2024-9381
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Ivanti CSA versions prior to 5.0.2
Description
The issue allows a remote authenticated attacker with admin privileges to bypass restrictions via path traversal. This can potentially lead to further exploitation. There is no information provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations
For Ivanti CSA versions prior to 5.0.2, upgrade to version 5.0.2 to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the admin web console to minimize the risk of exploitation.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ivanti Csa