CVE-2024-9379
KEVmoderateAuthenticated SQL Injection in Ivanti Cloud Services Appliance
CISA: Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability
Ivanti Cloud Services Appliance (CSA) versions prior to 5.0.2 contain a SQL injection vulnerability (CWE-89) in the admin web console. An attacker already authenticated as an administrator can submit crafted input that causes arbitrary SQL statements to execute against the appliance's backend database. Arbitrary SQL execution on the appliance could let an attacker read or alter database contents and take further actions on the appliance, depending on database privileges. The flaw affects CSA 4.6.x — which has reached end-of-life — and 5.0.x releases before 5.0.2. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2024-10-09 (ransomware use unknown), EPSS rates it a 43.8% chance of exploitation within 30 days (99th percentile), and neither a public proof of concept nor a CVSS score is available yet.
What to do: Upgrade CSA to version 5.0.2 or later; because the 4.6.x line is end-of-life and cannot be patched, remove 4.6.x appliances from service per CISA's required action. Restrict internet-facing access to the admin web console and review appliances for signs of compromise such as unexpected administrator logins or unusual database activity, treating remediation as urgent given the KEV listing and high EPSS score.
| Ivanti Cloud Services Appliance (CSA) | All versions prior to 5.0.2, including the end-of-life 4.6.x line |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
- Affected
- Ivanti Cloud Services Appliance (CSA)
- Required action
- As Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line, or later, of supported solution.
- Due date
- Ransomware use
- Unknown
- Vendors
- ivanti
- Products
- endpoint manager cloud services appliance
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H