216.73.216.233

CVE-2024-9380

· Published 09/10/2024 02:00 · Modified 21/12/2025 10:14 · Author: Cybersecurity and Infrastructure Security Agency

Labels: CVE-2024-9380 2024-10-083c1d8aa1-5a33-4ea4-8992-aadd6440af75CVE-2024-9380CWE-77CWE-78

Essential information

Published
09/10/2024 02:00
Modified
21/12/2025 10:14
Author
Cybersecurity and Infrastructure Security Agency
Creator
Cybersecurity and Infrastructure Security Agency
CVSS
7.2 HIGH (v3.1)
CISA KEV
Yes
CWE
CVSS vector
CVSS:3.1/AV:N/C:H/I:H/A:H

CVSS metrics

Description

Ivanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in the administrative console which can allow an authenticated attacker with application admin privileges to pass commands to the underlying OS.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
3c1d8aa1-5a33-4ea4-8992-aadd6440af75
NVD
View on NVD

Affected products (CPE)

ProductCPE
ivanti / endpoint manager cloud services appliance cpe:2.3:a:ivanti:endpoint_manager_cloud_services_appliance:*:*:*:*:*:*:*:*

References