← Back to browse · API

CVE-2024-9380

Severity
HIGH
CVSS
7.2
EPSS
0.62785
Risk score
75.77
CISA KEV
Yes
PoC
No
Published
2024-10-09
Modified
2024-10-09
First seen
2026-08-07
Aliases
EUVD-2024-49898, GHSA-V7HG-Q674-723G
Products
Ivanti:CSA (Cloud Services Appliance) patch: 5.0.2, Ivanti:Cloud Services Appliance (CSA)
Sources
euvd EUVD-2024-49898
cisa.gov CVE-2024-9380

Description

Ivanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in the administrative console which can allow an authenticated attacker with application admin privileges to pass commands to the underlying OS.

References