EXPOSURES › CVE-2024-9379
CVE-2024-9379
HIGH ⌖ ON CISA KEV · EXPLOITEDIvanti CSA admin console SQL injection allows authenticated admins to execute arbitrary SQL statements in versions prior to 5.0.2.
This SQL injection flaw in the Ivanti Cloud Services Appliance admin console enables remote attackers with admin credentials to execute arbitrary SQL commands, bypassing database integrity controls. DIB orgs must patch immediately to prevent data exfiltration or database manipulation, as the vulnerability is actively exploited and linked to ransomware campaigns despite not being a zero-day.
Shame score — The vulnerability is actively exploited and linked to ransomware, but it is not a zero-day and was disclosed publicly, indicating a responsible disclosure process.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Cloud Services Appliance (CSA) contains a SQL injection vulnerability in the admin web console in versions prior to 5.0.2, which can allow a remote attacker authenticated as administrator to run arbitrary SQL statements.
| PRODUCT | STATUS |
|---|---|
| Ivanti Neurons for ITSM (Formerly Service Manager) Ivanti |
Authorized |
| Ivanti Neurons for MDM (Formerly MobileIron) Ivanti |
Authorized |