← Back to browse · API

CVE-2024-9379

Severity
MEDIUM
CVSS
6.5
EPSS
0.43364
Risk score
66.18
CISA KEV
Yes
PoC
No
Published
2024-10-08
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2024-49897, GHSA-CP43-973G-2QQG
Products
Ivanti:CSA (Cloud Services Appliance) patch: 5.0.2, Ivanti:Cloud Services Appliance (CSA)
Sources
cisa.gov CVE-2024-9379
euvd EUVD-2024-49897

Description

SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.

References