CVE-2024-11773
CVSS 3.1 Score 9.1 of 10 (high)
Details
Summary
CVE-2024-11773 is a vulnerability affecting the Ivanti Cloud Service Automation (CSA) admin web console before version 5.0.3. An authenticated attacker with admin privileges can exploit this SQL injection flaw to execute arbitrary SQL statements remotely. This vulnerability poses a significant risk, as it allows unauthorized access and manipulation of sensitive data stored in Ivanti CSA databases. Successful exploitation could lead to data theft, data corruption, or even complete system compromise. Users are strongly encouraged to upgrade to the latest Ivanti CSA version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.