CVE-2024-9380
CVSS 3.1 Score 7.2 of 10 (high)
Details
Published Oct 8, 2024
Updated: Oct 10, 2024
CWE ID 78
CWE ID 77
Summary
CVE-2024-9380 is a critical vulnerability affecting Ivanti's Cloud Service Automation (CSA) before version 5.0.2. This issue permits a remote, authenticated attacker with administrative privileges to execute OS commands through the admin web console, leading to potential code execution. An attacker could exploit this vulnerability to gain unauthorized access, install malware, or steal sensitive data, making it imperative for organizations using Ivanti CSA to apply the necessary patch as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Ivanti