Junglewise Threat Intelligence

CVE-2024-8963: Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability

CVE-2024-8963 · Severity: critical · CVSS 9.4 · Exploited in the wild · Published 2024-09-19

Technologies: Ivanti Cloud Services Appliance (CSA). Vendors: Ivanti.

Executive brief

A path traversal vulnerability in Ivanti Cloud Services Appliance (CSA) allows a remote, unauthenticated attacker to access restricted functionality. When chained with CVE-2024-8190, this flaw can lead to administrative authentication bypass and arbitrary command execution.

Affected products

  • Ivanti Cloud Services Appliance (CSA) before 4.6 Patch 519

Timeline

  • 2024-09-19: disclosed: Initial disclosure by Ivanti and NVD publication.
  • 2024-09-19: kev added: Added to CISA's Known Exploited Vulnerabilities (KEV) catalog.
  • 2024-09-19: exploited: Reported as exploited in the wild.

Related threats