EXPOSURES › CVE-2024-9380
CVE-2024-9380
HIGH ⌖ ON CISA KEV · EXPLOITEDIvanti CSA admin console allows authenticated attackers to execute arbitrary OS commands via command injection.
An authenticated attacker with application admin privileges can inject and execute arbitrary OS commands through the Ivanti Cloud Services Appliance administrative console, enabling full system compromise. This RCE vulnerability is actively exploited in the wild and poses a severe risk to DIB organizations relying on Ivanti CSA for infrastructure management, requiring immediate patching and credential rotation.
Shame score — Active exploitation of a command injection flaw in a widely deployed infrastructure product indicates a critical security oversight.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in the administrative console which can allow an authenticated attacker with application admin privileges to pass commands to the underlying OS.
| PRODUCT | STATUS |
|---|---|
| Ivanti Neurons for ITSM (Formerly Service Manager) Ivanti |
Authorized |
| Ivanti Neurons for MDM (Formerly MobileIron) Ivanti |
Authorized |