EXPOSURES › CVE-2024-8190
CVE-2024-8190
HIGH ⌖ ON CISA KEV · EXPLOITEDIvanti Cloud Services Appliance allows authenticated admins to execute arbitrary OS commands via command injection in the admin console.
This vulnerability enables remote code execution for authenticated administrators, posing a severe risk to DIB organizations relying on Ivanti appliances for network management and security. The active exploitation status and command injection nature mean that compromised credentials could lead to full system compromise, violating NIST 800-171 and FedRAMP requirements for system integrity and access control. DIB orgs must immediately patch affected systems and audit all administrative access to prevent lateral movement.
Shame score — Active exploitation of a command injection vulnerability in a widely deployed network management appliance indicates a critical security oversight.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in the administrative console which can allow an authenticated attacker with application admin privileges to pass commands to the underlying OS.
| PRODUCT | STATUS |
|---|---|
| Ivanti Neurons for ITSM (Formerly Service Manager) Ivanti |
Authorized |
| Ivanti Neurons for MDM (Formerly MobileIron) Ivanti |
Authorized |