Junglewise Threat Intelligence

CVE-2024-9380: Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability

CVE-2024-9380 · Severity: critical · CVSS 7.2 · Exploited in the wild · Published 2024-10-09

Technologies: Ivanti Cloud Services Appliance (CSA). Vendors: Ivanti.

Executive brief

An OS command injection vulnerability in the administrative web console of Ivanti Cloud Services Appliance (CSA) allows a remote authenticated attacker with administrator privileges to execute arbitrary commands on the underlying operating system. This vulnerability has been observed being exploited in the wild.

Affected products

  • Ivanti Cloud Services Appliance (CSA) before 5.0.2

Timeline

  • 2024-10-08: disclosed: CVE received from Ivanti and published to NVD
  • 2024-10-09: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog
  • 2024-10-09: exploited: Reported as exploited in the wild
  • 2024-10-09: advisory: Ivanti security advisory published

Related threats