Executive brief
A path traversal vulnerability in Ivanti Cloud Services Appliance (CSA) allows a remote, unauthenticated attacker to access restricted functionality. When chained with CVE-2024-8190, this flaw can lead to administrative authentication bypass and arbitrary command execution.
Affected products
- Ivanti Cloud Services Appliance (CSA) before 4.6 Patch 519
Timeline
- 2024-09-19: disclosed: Initial disclosure by Ivanti and NVD publication.
- 2024-09-19: kev added: Added to CISA's Known Exploited Vulnerabilities (KEV) catalog.
- 2024-09-19: exploited: Reported as exploited in the wild.