CVE-2024-8963

CRITICAL9.4Pubblicata il 19 settembre 2024

Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.

Sfruttata attivamente

  • Nel catalogo CISA delle vulnerabilità sfruttate dal 19 set 2024
  • Le agenzie federali statunitensi devono correggerla entro il 10 ott 2024 (direttiva BOD 22-01)
  • Attaccata 1 giorno prima che la vulnerabilità fosse resa pubblica
  • Confermata dai sensori, non solo da segnalazioni

As Ivanti CSA has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line of supported solutions, as future vulnerabilities on the 4.6.x version of CSA are unlikely to receive security updates.

Fonte: CISA KEV · 1 set 2026 1 set 2026 31 ago 2026 30 ago 2026 30 ago 2026 29 ago 2026

Punteggio CVSS9.4 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Tipo di debolezza (CWE)CWE-22, CWE-22
Vendorivanti

Prodotti coinvolti

VendorProdottoVersioni
ivantiendpoint manager cloud services appliance4.6

Articoli correlati

This product uses the NVD API but is not endorsed or certified by the NVD.

Database CVE