Executive brief
An OS command injection vulnerability in the Ivanti Cloud Services Appliance (CSA) administrative console allows a remote authenticated attacker with admin-level privileges to execute arbitrary commands on the underlying operating system. This vulnerability has been observed being exploited in the wild.
Affected products
- Ivanti Cloud Services Appliance (CSA) 4.6 Patch 518 and before
Timeline
- 2024-09-10: disclosed: Initial CVE entry received from Ivanti
- 2024-09-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-09-13: advisory: Ivanti security advisory published