Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Oct 30, 2024

CVE-2024-9379

High
EPSS 81.7%CISA KEV
Ivanti/Cloud Services Appliance (CSA)

Description

Ivanti Cloud Services Appliance (CSA) contains a SQL injection vulnerability in the admin web console in versions prior to 5.0.2, which can allow a remote attacker authenticated as administrator to run arbitrary SQL statements.

EPSS — Exploit Probability

81.7%

Higher than 99.2% of all CVEs

Required Action

https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-CSA-Cloud-Services-Appliance-CVE-2024-9379-CVE-2024-9380-CVE-2024-9381 ; https://nvd.nist.gov/vuln/detail/CVE-2024-9379

Risk Assessment

HIGH
In CISA KEV
High EPSS

Details

Severity
High
EPSS
81.7%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

Oct 9, 2024

Added to KEV

Oct 9, 2024

Remediation Due

Oct 30, 2024

Affected Product

Ivanti

Cloud Services Appliance (CSA)

View all Ivanti CVEs