CVE-2024-9379

Ivanti CSA (Cloud Services Appliance)

Published 8 Oct 2024 · updated 1 Oct 2026 · Analyzed

7.2 High · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 9 Oct 2024, with a remediation deadline of 30 Oct 2024 for US federal agencies.

Required action: As Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line, or later, of supported solution.

Description

SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.

References