CVE-2024-8963
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.
Explotada activamente
- En el catálogo CISA de vulnerabilidades explotadas desde el 19 sept 2024
- Las agencias federales de EE. UU. deben corregirla antes del 10 oct 2024 (BOD 22-01)
- Atacada 1 día antes de que la vulnerabilidad se hiciera pública
- Confirmada por sensores, no solo por informes
As Ivanti CSA has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line of supported solutions, as future vulnerabilities on the 4.6.x version of CSA are unlikely to receive security updates.
Fuente: CISA KEV · 1 sept 2026 1 sept 2026 31 ago 2026 30 ago 2026 30 ago 2026 29 ago 2026
Puntuación CVSS9.4 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:LTipo de debilidad (CWE)CWE-22, CWE-22
Fabricantesivanti
Productos afectados
| Fabricantes | Prodotto | Versioni |
|---|---|---|
| ivanti | endpoint manager cloud services appliance | 4.6 |
Artículos relacionados
This product uses the NVD API but is not endorsed or certified by the NVD.
