Executive brief
A code injection vulnerability in the Ivanti Endpoint Manager Cloud Services Appliance (CSA) allows an unauthenticated remote attacker to execute arbitrary code with limited 'nobody' permissions. The flaw stems from improper control of generation of code (CWE-94).
Affected products
- Ivanti Endpoint Manager Cloud Services Appliance (CSA) 4.5, 4.6
Timeline
- 2021-12-02: advisory: Vendor advisory SA-2021-12-02 published
- 2021-12-08: disclosed: NVD Published Date
- 2024-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-03-25: exploited: Reported as exploited in the wild by CISA