CVE-2024-8190
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.
Actively exploited
- In the CISA exploited-vulnerabilities catalogue since Sep 13, 2024
- US federal agencies must remediate it by Oct 4, 2024 (BOD 22-01)
- First attack observed 2 days after disclosure
As Ivanti CSA has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line of supported solutions, as future vulnerabilities on the 4.6.x version of CSA are unlikely to receive future security updates.
Source: CISA KEV · Sep 1, 2026 Aug 26, 2026 Aug 26, 2026 Mar 13, 2026 Mar 9, 2026 Jan 20, 2026
CVSS score7.2 / 10
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HWeakness type (CWE)CWE-78, CWE-78
Vendorsivanti
Affected products
| Vendors | Prodotto | Versioni |
|---|---|---|
| ivanti | cloud services appliance | 4.6 |
Related articles
This product uses the NVD API but is not endorsed or certified by the NVD.
