CVE-2021-44529
KEV ransomware PoC ×2moderateUnauthenticated Code Injection RCE in Ivanti Endpoint Manager Cloud Services Appliance
CISA: Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability
CVE-2021-44529 is a critical (CVSS 9.8) code injection flaw (CWE-94) in the web interface of Ivanti Endpoint Manager Cloud Services Appliance (CSA), a perimeter gateway used to remotely manage Ivanti Endpoint Manager deployments. An unauthenticated attacker can send crafted network requests to the appliance and inject code that executes on the device with the low-privilege 'nobody' account, requiring no credentials or user interaction. Successful exploitation yields remote code execution and a foothold on an internet-facing device, which attackers can use to pivot into internal networks and, per CISA, support ransomware operations. Organizations running CSA versions 4.5 and 4.6, the versions referenced in public PoCs, are affected, especially where the appliance is reachable from the internet. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-03-25 with ransomware use marked as known, and its EPSS score of 99.1% (100th percentile) indicates near-certain exploitation probability within 30 days.
What to do: Upgrade CSA 4.5 and 4.6 appliances to the patched releases per Ivanti's security advisory (or the latest CSA release), and until patched, restrict or firewall the CSA web interface away from direct internet exposure. Because CISA lists ransomware use as known, review appliance logs and integrity for signs of exploitation before assuming systems are clean. If mitigations are unavailable, CISA's required action is to discontinue use of the product.
| Ivanti Endpoint Manager Cloud Services Appliance (EPM CSA) | CSA 4.5 and 4.6 (versions referenced in public PoCs; confirm exact fixed releases against Ivanti's security advisory) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
- Affected
- Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA)
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Known
- Vendors
- ivanti
- Products
- endpoint manager cloud services appliance
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H