CVE-2024-8190
Ivanti CSA (Cloud Services Appliance), ivanti endpoint_manager_cloud_services_appliance
Published 10 Sept 2024 · updated 17 Jun 2026 · Analyzed
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 13 Sept 2024, with a remediation deadline of 4 Oct 2024 for US federal agencies.
Required action: As Ivanti CSA has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line of supported solutions, as future vulnerabilities on the 4.6.x version of CSA are unlikely to receive future security updates.
Description
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.
References
- forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Service-Appliance-CSA-CVE-2024-8190 · Vendor Advisory
- www.cisa.gov/news-events/alerts/2024/09/13/ivanti-releases-security-update-cloud-services-appliance · US Government Resource
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-8190 · US Government Resource