← Back to browse · API

CVE-2024-8190

Severity
HIGH
CVSS
7.2
EPSS
0.89122
Risk score
84.99
CISA KEV
Yes
PoC
No
Published
2024-09-13
Modified
2024-09-13
First seen
2026-08-07
Aliases
EUVD-2024-49004, GHSA-QJX2-RCX8-QR2R
Products
Ivanti:CSA (Cloud Services Appliance) patch: 4.6 Patch 519, Ivanti:CSA (Cloud Services Appliance) patch: 5.0, Ivanti:Cloud Services Appliance
Sources
euvd EUVD-2024-49004
cisa.gov CVE-2024-8190

Description

Ivanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in the administrative console which can allow an authenticated attacker with application admin privileges to pass commands to the underlying OS.

References