CVE-2024-9379

Published Oct 8, 2024

Last updated a month ago

Overview

Description
SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
Source
3c1d8aa1-5a33-4ea4-8992-aadd6440af75
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
7.2
Impact score
5.9
Exploitability score
1.2
Vector string
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability
Exploit added on
Oct 9, 2024
Exploit action due
Oct 30, 2024
Required action
As Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line, or later, of supported solution.

Weaknesses

nvd@nist.gov
CWE-89
3c1d8aa1-5a33-4ea4-8992-aadd6440af75
CWE-89

Social media

Hype score
Not currently trending

Configurations