- Description
- Command injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
- Source
- 3c1d8aa1-5a33-4ea4-8992-aadd6440af75
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 7.2
- Impact score
- 5.9
- Exploitability score
- 1.2
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- Hype score
- Not currently trending
Ivanti Cloud Service Appliance(CSA)の管理ウェブコンソールには、バージョン5.0.3より前に脆弱性が確認されています(CVE-2024-11639、CVE-2024-11772、CVE-2024-11773) CVE-2024-11639 CVSS 10.0 Criticalは、認証バイパスで認証されていない攻撃者が管理者権限を取得することが可能です。 https://t.co/Gntcq43qmU
@t_nihonmatsu
12 Dec 2024
275 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
Critical Flaw in Ivanti Cloud Services Application: Immediate Patch Recommended Stay secure with Ivanti Cloud Services Application (CSA) updates. Learn about critical security patches for CVE-2024-11639 (CVSS 10), CVE-2024-11772, and CVE-2024-11773 https://t.co/yB6SiQ05Lu
@the_yellow_fall
11 Dec 2024
88 Impressions
2 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
🚨Critical Ivanti Vulnerabilities🚨 Admin Authentication Bypass in Ivanti CSA (CVSS 10) : https://t.co/LKTJunMyXW CVE-2024-11639 Remote Code Executions in Ivanti CSA Admin Console (CVSS 9.1): https://t.co/nEEzJyyQt0 CVE-2024-11772 https://t.co/NFPFji3wrS CVE-2024-11773 #vulmon
@vulmoncom
10 Dec 2024
244 Impressions
1 Retweet
1 Like
2 Bookmarks
1 Reply
0 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ivanti:cloud_services_appliance:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "60628283-69C1-4274-9BC8-5C2B91A7AA6E",
"versionEndExcluding": "5.0.3"
}
],
"operator": "OR"
}
]
}
]