Skip to content
COOEY

EXPOSURES › CVE-2024-8963

CVE-2024-8963

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-09-19 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-8963 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatchedransomware

Ivanti CSA path traversal vulnerability enables remote unauthenticated access and, when combined with CVE-2024-8190, allows arbitrary command execution.

This unpatched vulnerability allows remote attackers to bypass admin authentication and execute arbitrary commands on the Cloud Services Appliance, posing a critical RCE risk for DIB organizations relying on Ivanti infrastructure. The combination of CVE-2024-8963 and CVE-2024-8190 creates a high-severity chain that could lead to full system compromise, necessitating immediate patching and network segmentation to prevent unauthorized access.

Shame score — The vulnerability was actively exploited in the wild and linked to ransomware campaigns, indicating a failure to patch a known, high-severity issue promptly.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Ivanti Cloud Services Appliance (CSA) contains a path traversal vulnerability that could allow a remote, unauthenticated attacker to access restricted functionality. If CVE-2024-8963 is used in conjunction with CVE-2024-8190, an attacker could bypass admin authentication and execute arbitrary commands on the appliance.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Ivanti Neurons for ITSM (Formerly Service Manager)
Ivanti
Authorized
Ivanti Neurons for MDM (Formerly MobileIron)
Ivanti
Authorized