Skip to content
COOEY

EXPOSURES › CVE-2024-8190

CVE-2024-8190

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-09-13 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-8190 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 65/100 rceexploited-in-wildunpatched

Ivanti Cloud Services Appliance allows authenticated admins to execute arbitrary OS commands via command injection in the admin console.

This vulnerability enables remote code execution for authenticated administrators, posing a severe risk to DIB organizations relying on Ivanti appliances for network management and security. The active exploitation status and command injection nature mean that compromised credentials could lead to full system compromise, violating NIST 800-171 and FedRAMP requirements for system integrity and access control. DIB orgs must immediately patch affected systems and audit all administrative access to prevent lateral movement.

Shame score — Active exploitation of a command injection vulnerability in a widely deployed network management appliance indicates a critical security oversight.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Ivanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in the administrative console which can allow an authenticated attacker with application admin privileges to pass commands to the underlying OS.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Ivanti Neurons for ITSM (Formerly Service Manager)
Ivanti
Authorized
Ivanti Neurons for MDM (Formerly MobileIron)
Ivanti
Authorized