ZeroHour

CVE-2024-11773

moderate

SQL Injection in Ivanti Cloud Services Appliance Admin Console (pre-5.0.3)

CVSS 3.1
7.2 high
EPSS
24%p98
Published
()
Modified
AI analysis

CVE-2024-11773 is a SQL injection flaw (CWE-89) in the admin web console of Ivanti's Cloud Services Appliance (CSA), affecting all versions before 5.0.3. A remote attacker who has authenticated to the admin console with administrator privileges can submit crafted input that injects arbitrary SQL statements into the appliance's back-end database. Successful exploitation could allow reading or modifying database contents, such as extracting stored data or tampering with the appliance, consistent with the high confidentiality, integrity, and availability impact reflected in the 7.2 CVSS score. Only organizations running Ivanti CSA prior to 5.0.3 are affected, and exploitation requires valid admin credentials, which limits the practical attack surface. No public proof-of-concept or confirmed in-the-wild exploitation is known, but the high EPSS score (23.6%, 98th percentile) indicates a meaningful chance of exploitation within 30 days, and Ivanti shipped the fix in 5.0.3 as part of a broader CSA and Connect Secure security update.

What to do: Upgrade Ivanti CSA to version 5.0.3 or later immediately, as this is the first fixed release. Until patched, restrict access to the CSA admin console to trusted networks via firewall or VPN allowlisting, enforce strong admin credentials, and review admin console and database logs for signs of SQL injection or unusual queries. Note that the 5.0.3 update addresses other CSA and Connect Secure vulnerabilities as well, so apply the full update set rather than a partial fix.

Affected
Ivanti Cloud Services Appliance (CSA)All versions before 5.0.3 (fixed in 5.0.3)
Estimated exposure
moderatelow thousands of deployed CSA appliances (approximately 1k-10k worldwide) — CSA is a specialized DMZ gateway appliance deployed only by organizations using Ivanti (formerly MobileIron) cloud services, so the installed base is plausibly in the low thousands rather than mass-market, with the admin-authentication…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SQL injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.

Vendors
ivanti
Products
cloud services appliance
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news