216.73.216.233

CVE-2024-9379

· Published 09/10/2024 02:00 · Modified 21/12/2025 10:14 · Author: Cybersecurity and Infrastructure Security Agency

Labels: CVE-2024-9379 2024-10-083c1d8aa1-5a33-4ea4-8992-aadd6440af75CVE-2024-9379CWE-89

Essential information

Published
09/10/2024 02:00
Modified
21/12/2025 10:14
Author
Cybersecurity and Infrastructure Security Agency
Creator
Cybersecurity and Infrastructure Security Agency
CVSS
6.5 MEDIUM (v3.1)
CISA KEV
Yes
CWE
CVSS vector
CVSS:3.1/AV:N/C:N/I:H/A:H

CVSS metrics

Description

Ivanti Cloud Services Appliance (CSA) contains a SQL injection vulnerability in the admin web console in versions prior to 5.0.2, which can allow a remote attacker authenticated as administrator to run arbitrary SQL statements.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
3c1d8aa1-5a33-4ea4-8992-aadd6440af75
NVD
View on NVD

Affected products (CPE)

ProductCPE
ivanti / endpoint manager cloud services appliance cpe:2.3:a:ivanti:endpoint_manager_cloud_services_appliance:*:*:*:*:*:*:*:*

References