Skip to content
COOEY

EXPOSURES › CVE-2024-9380

CVE-2024-9380

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-10-09 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-9380 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 65/100 rceexploited-in-wildsupply-chain

Ivanti CSA admin console allows authenticated attackers to execute arbitrary OS commands via command injection.

An authenticated attacker with application admin privileges can inject and execute arbitrary OS commands through the Ivanti Cloud Services Appliance administrative console, enabling full system compromise. This RCE vulnerability is actively exploited in the wild and poses a severe risk to DIB organizations relying on Ivanti CSA for infrastructure management, requiring immediate patching and credential rotation.

Shame score — Active exploitation of a command injection flaw in a widely deployed infrastructure product indicates a critical security oversight.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Ivanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in the administrative console which can allow an authenticated attacker with application admin privileges to pass commands to the underlying OS.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Ivanti Neurons for ITSM (Formerly Service Manager)
Ivanti
Authorized
Ivanti Neurons for MDM (Formerly MobileIron)
Ivanti
Authorized