ZeroHour

CVE-2024-9379

KEVmoderate

Authenticated SQL Injection in Ivanti Cloud Services Appliance

CISA: Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability

CVSS 3.1
7.2 high
EPSS
44%p99
Published
()
KEV added
AI analysis

Ivanti Cloud Services Appliance (CSA) versions prior to 5.0.2 contain a SQL injection vulnerability (CWE-89) in the admin web console. An attacker already authenticated as an administrator can submit crafted input that causes arbitrary SQL statements to execute against the appliance's backend database. Arbitrary SQL execution on the appliance could let an attacker read or alter database contents and take further actions on the appliance, depending on database privileges. The flaw affects CSA 4.6.x — which has reached end-of-life — and 5.0.x releases before 5.0.2. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2024-10-09 (ransomware use unknown), EPSS rates it a 43.8% chance of exploitation within 30 days (99th percentile), and neither a public proof of concept nor a CVSS score is available yet.

What to do: Upgrade CSA to version 5.0.2 or later; because the 4.6.x line is end-of-life and cannot be patched, remove 4.6.x appliances from service per CISA's required action. Restrict internet-facing access to the admin web console and review appliances for signs of compromise such as unexpected administrator logins or unusual database activity, treating remediation as urgent given the KEV listing and high EPSS score.

Affected
Ivanti Cloud Services Appliance (CSA)All versions prior to 5.0.2, including the end-of-life 4.6.x line
Estimated exposure
moderate≈ a few thousand internet-exposed CSA appliances (total installed base unknown) — Ivanti CSA is a specialized gateway appliance deployed mainly by enterprises that manage endpoints with Ivanti products; public internet scans have shown only a few thousand exposed instances, and Ivanti does not publish install counts, so…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.

CISA Known Exploited Vulnerability
Affected
Ivanti Cloud Services Appliance (CSA)
Required action
As Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line, or later, of supported solution.
Due date
Ransomware use
Unknown
Vendors
ivanti
Products
endpoint manager cloud services appliance
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news