Aller au contenu

Fiche vulnérabilité

CVE-2024-8190 : faille exploitée ivanti cloud services appliance (CVSS 7.2)

Description

An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.

En bref

Sévérité
Élevée (CVSS 7.2)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Oui, inscrite au catalogue CISA KEV
Publication
10 sept. 2024
Dernière mise à jour
17 juin 2026

Produits concernés

  • ivanti cloud services appliance

Correctif et mesures

As Ivanti CSA has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line of supported solutions, as future vulnerabilities on the 4.6.x version of CSA are unlikely to receive future security updates.

Références

Rechercher une autre vulnérabilité dans la base CVE