CVE-2024-11773
moderateSQL Injection in Ivanti Cloud Services Appliance Admin Console (pre-5.0.3)
CVE-2024-11773 is a SQL injection flaw (CWE-89) in the admin web console of Ivanti's Cloud Services Appliance (CSA), affecting all versions before 5.0.3. A remote attacker who has authenticated to the admin console with administrator privileges can submit crafted input that injects arbitrary SQL statements into the appliance's back-end database. Successful exploitation could allow reading or modifying database contents, such as extracting stored data or tampering with the appliance, consistent with the high confidentiality, integrity, and availability impact reflected in the 7.2 CVSS score. Only organizations running Ivanti CSA prior to 5.0.3 are affected, and exploitation requires valid admin credentials, which limits the practical attack surface. No public proof-of-concept or confirmed in-the-wild exploitation is known, but the high EPSS score (23.6%, 98th percentile) indicates a meaningful chance of exploitation within 30 days, and Ivanti shipped the fix in 5.0.3 as part of a broader CSA and Connect Secure security update.
What to do: Upgrade Ivanti CSA to version 5.0.3 or later immediately, as this is the first fixed release. Until patched, restrict access to the CSA admin console to trusted networks via firewall or VPN allowlisting, enforce strong admin credentials, and review admin console and database logs for signs of SQL injection or unusual queries. Note that the 5.0.3 update addresses other CSA and Connect Secure vulnerabilities as well, so apply the full update set rather than a partial fix.
| Ivanti Cloud Services Appliance (CSA) | All versions before 5.0.3 (fixed in 5.0.3) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
SQL injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
- Vendors
- ivanti
- Products
- cloud services appliance
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H