CVE-2024-8190

HIGH7.2Published on September 10, 2024

An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.

Actively exploited

  • In the CISA exploited-vulnerabilities catalogue since Sep 13, 2024
  • US federal agencies must remediate it by Oct 4, 2024 (BOD 22-01)
  • First attack observed 2 days after disclosure

As Ivanti CSA has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line of supported solutions, as future vulnerabilities on the 4.6.x version of CSA are unlikely to receive future security updates.

Source: CISA KEV · Sep 1, 2026 Aug 26, 2026 Aug 26, 2026 Mar 13, 2026 Mar 9, 2026 Jan 20, 2026

CVSS score7.2 / 10CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness type (CWE)CWE-78, CWE-78
Vendorsivanti

Affected products

VendorsProdottoVersioni
ivanticloud services appliance4.6

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database