CVE-2024-9380
unknown
KEV
CVSS v3
—
CVSS v2
—
VIR risk
1.5
Description
Ivanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in the administrative console which can allow an authenticated attacker with application admin privileges to pass commands to the underlying OS.
CISA KEV
- Vendor
- Ivanti
- Product
- Cloud Services Appliance (CSA)
- Due date
- 2024-10-30
Predictions
Exploit likelihood
99%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cisa-kev — https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-CSA-Cloud-Services-Appliance-CVE-2024-9379-CVE-2024-9380-CVE-2024-9381 ; https://nvd.nist.gov/vuln/detail/CVE-2024-9380
Exploits
References
Verify integrity in audit chain (admin only). AS-IS.