PT-2024-7355 · Ivanti · Ivanti Csa

Published

2024-10-08

·

Updated

2025-02-11

·

CVE-2024-9381

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Ivanti CSA versions prior to 5.0.2
Description The issue allows a remote authenticated attacker with admin privileges to bypass restrictions via path traversal. This can potentially lead to further exploitation. There is no information provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations For Ivanti CSA versions prior to 5.0.2, upgrade to version 5.0.2 to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the admin web console to minimize the risk of exploitation.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2024-08717
CVE-2024-9381

Affected Products

Ivanti Csa