ZeroHour

CVE-2024-47908

moderate

OS Command Injection in Ivanti Cloud Services Appliance Admin Console Enables Admin RCE

CVSS 3.1
7.2 high
EPSS
22%p98
Published
()
Modified
AI analysis

CVE-2024-47908 is an OS command injection flaw (CWE-78) in the admin web console of Ivanti's Cloud Services Appliance (CSA), fixed in version 5.0.5. A remote attacker who has authenticated with administrator privileges to the console can inject operating system commands and achieve remote code execution on the appliance. Because the console is typically reachable over the network and high-privileged credentials are the only barrier, risk depends heavily on admin credential hygiene and how widely the admin interface is exposed. All CSA deployments running versions before 5.0.5 are affected. There is no known public proof-of-concept and the flaw is not yet in the CISA KEV catalog, so no confirmed in-the-wild exploitation is currently documented, though EPSS assigns a fairly high ~22% probability of exploitation within 30 days.

What to do: Upgrade Ivanti CSA to version 5.0.5 or later as the primary remediation. Until patched, restrict access to the admin web console to trusted management networks (VPN/allowlist), enforce strong and unique admin credentials with MFA where available, and review appliance logs for unusual commands or unexpected admin sessions. Monitor Ivanti advisories, as the vendor has recently patched multiple CSA and Connect Secure issues and exploitation activity may follow.

Affected
Ivanti Cloud Services Appliance (CSA)all versions before 5.0.5
Estimated exposure
moderateplausibly on the order of thousands of deployed CSA appliances (1k–10k range), many internet-exposed — CSA is a niche virtual appliance typically deployed roughly one-per-service-organization by Ivanti partners and MSPs rather than at enterprise fleet scale, and public internet scans have historically surfaced only a few thousand exposed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

Vendors
ivanti
Products
cloud services appliance
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news