CVE-2024-11639

Published Dec 10, 2024

Last updated a month ago

Overview

Description
An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access
Source
3c1d8aa1-5a33-4ea4-8992-aadd6440af75
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

3c1d8aa1-5a33-4ea4-8992-aadd6440af75
CWE-288
nvd@nist.gov
CWE-306

Social media

Hype score
Not currently trending
  1. 🚨 Ivanti warns of a critical authentication bypass #vulnerability (CVE-2024-11639) in its #CloudServicesAppliance, allowing attackers to gain admin access remotely. Protect your environment—read the #CybersecurityThreatAdvisory now: https://t.co/y29BPoDxAY

    @SmarterMSP

    24 Dec 2024

    65 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨 Ivanti has disclosed a maximum-severity authentication bypass vulnerability (CVE-2024-11639) in its CSA solution. @BleepinComputer shares this flaw allows remote attackers to gain admin privileges on vulnerable appliances without authentication or user interaction. Learn more:

    @RapidFortInc

    20 Dec 2024

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Ivanti has released patches for critical flaws in Cloud Services Application, Connect Secure and Policy Secure. The most critical vulnerability, CVE-2024-11639, has a CVSS score of 10.0 https://t.co/iPVE76WIfi #CyberSecurity #Patching #Ivanti #VulnerabilityManagement

    @DataConnectUK

    13 Dec 2024

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Ivanti Cloud Service Appliance(CSA)の管理ウェブコンソールには、バージョン5.0.3より前に脆弱性が確認されています(CVE-2024-11639、CVE-2024-11772、CVE-2024-11773) CVE-2024-11639 CVSS 10.0 Criticalは、認証バイパスで認証されていない攻撃者が管理者権限を取得することが可能です。 https://t.co/Gntcq43qmU

    @t_nihonmatsu

    12 Dec 2024

    275 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  5. Maximum Severity: Ivanti Patches Critical CSA Vulnerability (CVE-2024-11639) https://t.co/rv7OiLAZ6C

    @the_yellow_fall

    12 Dec 2024

    164 Impressions

    0 Retweets

    4 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. ℹ️ Ivanti publie des mises à jour critiques pour les vulnérabilités CSA et Connect Secure. Privilège d'escalade et exécution de code possibles. CVE-2024-11639 (CVSS 10.0) inclus. Pour les Analystes Sécurité très avertis. #Cybersecurité #Vulnérabilités 👉 https://t.co/2zmEKruzpJ

    @CyberAlertFr

    12 Dec 2024

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🚨 CVE Alert: Critical Ivanti Cloud Services Application (CSA) Authentication Bypass Vulnerability🚨 Vulnerability Details: CVE-2024-11639 (CVSS v3 10/10) Ivanti Cloud Services Application (CSA) Authentication Bypass Vulnerability Impact A Successful exploit may allows a remote

    @CyberxtronTech

    12 Dec 2024

    79 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Ivanti has issued an urgent warning about three more critical vulnerabilities affecting its Cloud Services Application (CSA), including a perfect 10. 🔴 CVE-2024-11639 (CVSS 10.0): This max-rating vulnerability allows unauthenticated attackers to bypass authentication mechanisms

    @cytexsmb

    11 Dec 2024

    830 Impressions

    2 Retweets

    4 Likes

    1 Bookmark

    0 Replies

    2 Quotes

  9. Ivanti warns of maximum severity CSA auth bypass vulnerability: https://t.co/Twj5oV5lAU Ivanti has issued a warning regarding a maximum-severity authentication bypass vulnerability (CVE-2024-11639) in its Cloud Services Appliance (CSA) 5.0.2 and earlier, allowing remote… https:/

    @securityRSS

    11 Dec 2024

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. #Ivanti has a new maximum-severity authentication bypass #vulnerability CVE-2024-11639 in its Cloud Services Appliance (CSA) solution. Patch now! 👇 https://t.co/eT47Aq0gW9

    @securestep9

    11 Dec 2024

    212 Impressions

    2 Retweets

    5 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. ⚠️⚠️ CVE-2024-11639 (CVSS 10) – Critical Flaw in Ivanti Cloud Services Application: Immediate Patch Recommended 🎯6.9k+ Results are found on the https://t.co/pb16tGYaKe nearly year. 🔗FOFA Link:https://t.co/LsgNAKJIZJ FOFA Query:app="Ivanti(R)-Cloud-Services-Appliance" 🔖… ht

    @fofabot

    11 Dec 2024

    812 Impressions

    2 Retweets

    8 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  12. Critical Flaw in Ivanti Cloud Services Application: Immediate Patch Recommended Stay secure with Ivanti Cloud Services Application (CSA) updates. Learn about critical security patches for CVE-2024-11639 (CVSS 10), CVE-2024-11772, and CVE-2024-11773 https://t.co/yB6SiQ05Lu

    @the_yellow_fall

    11 Dec 2024

    88 Impressions

    2 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  13. Ivanti warned customers about a new maximum-severity authentication bypass vulnerability in its Cloud Services Appliance (CSA) solution. The security flaw (tracked as CVE-2024-11639 and reported by CrowdStrike's Advanced Research Team) enables remote attackers to gain… https://t

    @Senshin108

    11 Dec 2024

    106 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. 🚨Critical Ivanti Vulnerabilities🚨 Admin Authentication Bypass in Ivanti CSA (CVSS 10) : https://t.co/LKTJunMyXW CVE-2024-11639 Remote Code Executions in Ivanti CSA Admin Console (CVSS 9.1): https://t.co/nEEzJyyQt0 CVE-2024-11772 https://t.co/NFPFji3wrS CVE-2024-11773 #vulmon

    @vulmoncom

    10 Dec 2024

    244 Impressions

    1 Retweet

    1 Like

    2 Bookmarks

    1 Reply

    0 Quotes

Configurations