CVE-2024-8963
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.
Sfruttata attivamente
- Nel catalogo CISA delle vulnerabilità sfruttate dal 19 set 2024
- Le agenzie federali statunitensi devono correggerla entro il 10 ott 2024 (direttiva BOD 22-01)
- Attaccata 1 giorno prima che la vulnerabilità fosse resa pubblica
- Confermata dai sensori, non solo da segnalazioni
As Ivanti CSA has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line of supported solutions, as future vulnerabilities on the 4.6.x version of CSA are unlikely to receive security updates.
Fonte: CISA KEV · 1 set 2026 1 set 2026 31 ago 2026 30 ago 2026 30 ago 2026 29 ago 2026
Punteggio CVSS9.4 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:LTipo di debolezza (CWE)CWE-22, CWE-22
Vendorivanti
Prodotti coinvolti
| Vendor | Prodotto | Versioni |
|---|---|---|
| ivanti | endpoint manager cloud services appliance | 4.6 |
Articoli correlati
This product uses the NVD API but is not endorsed or certified by the NVD.
