CVE-2024-47908
moderateOS Command Injection in Ivanti Cloud Services Appliance Admin Console Enables Admin RCE
CVE-2024-47908 is an OS command injection flaw (CWE-78) in the admin web console of Ivanti's Cloud Services Appliance (CSA), fixed in version 5.0.5. A remote attacker who has authenticated with administrator privileges to the console can inject operating system commands and achieve remote code execution on the appliance. Because the console is typically reachable over the network and high-privileged credentials are the only barrier, risk depends heavily on admin credential hygiene and how widely the admin interface is exposed. All CSA deployments running versions before 5.0.5 are affected. There is no known public proof-of-concept and the flaw is not yet in the CISA KEV catalog, so no confirmed in-the-wild exploitation is currently documented, though EPSS assigns a fairly high ~22% probability of exploitation within 30 days.
What to do: Upgrade Ivanti CSA to version 5.0.5 or later as the primary remediation. Until patched, restrict access to the admin web console to trusted management networks (VPN/allowlist), enforce strong and unique admin credentials with MFA where available, and review appliance logs for unusual commands or unexpected admin sessions. Monitor Ivanti advisories, as the vendor has recently patched multiple CSA and Connect Secure issues and exploitation activity may follow.
| Ivanti Cloud Services Appliance (CSA) | all versions before 5.0.5 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
- Vendors
- ivanti
- Products
- cloud services appliance
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H