Skip to content
COOEY

FAIL › dossier

Cloud Services Appliance (CSA)

PRODUCT

· dossier confidence 60%

Cloud Services Appliance (CSA) by Ivanti suffered three critical RCE vulnerabilities in 2024, including path traversal and command injection flaws that enabled remote code execution.

PROFILE
CategoryCloud Services ApplianceWhat they doCloud Services Appliance (CSA) is a product line from Ivanti that provides cloud-based IT management and security solutions.
SECURITY POSTURE

Critical security vulnerabilities discovered in Q3-Q4 2024, including remote code execution (RCE) and SQL injection flaws in the admin console.

Notable failures
  • CVE-2024-8963: Remote unauthenticated RCE via path traversal
  • CVE-2024-9380: Authenticated RCE via command injection
  • CVE-2024-9379: Authenticated SQL injection in admin console
Patterns: Repeated high-severity RCE vulnerabilities in cloud appliance products; Command injection and SQL injection in admin interfaces
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2024-09-19 CVE-2024-8963 high Ivanti CSA path traversal vulnerability enables remote unauthenticated access and, when combined with CVE-2024-8190, allows arbitrary command execution.
2024-10-09 CVE-2024-9380 high Ivanti CSA admin console allows authenticated attackers to execute arbitrary OS commands via command injection.
2024-10-09 CVE-2024-9379 high Ivanti CSA admin console SQL injection allows authenticated admins to execute arbitrary SQL statements in versions prior to 5.0.2.
Open questions: Ivanti CSA product launch date and headquarters location · Current security patch status for CVE-2024-8963, CVE-2024-9380, CVE-2024-9379 · Ivanti CSA customer base and market share
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-31 03:55:01.967274+00:00