CVE-2024-8963

Ivanti CSA (Cloud Services Appliance), ivanti endpoint_manager_cloud_services_appliance

Published 19 Sept 2024 · updated 17 Jun 2026 · Analyzed

9.1 Critical · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 19 Sept 2024, with a remediation deadline of 10 Oct 2024 for US federal agencies.

Required action: As Ivanti CSA has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line of supported solutions, as future vulnerabilities on the 4.6.x version of CSA are unlikely to receive security updates.

Description

Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.

References