CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-11772

CVSS 9.1v3.1pub. 2024-12-10upd. 2025-01-17

Command injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

🤖 AI Analysis
How it works

The vulnerability lies in insufficient input validation in the administration console of the Ivanti CSA web application, which is classified as command injection (CWE-77). An attacker with an administrator account can submit crafted data containing malicious system commands that will be executed by the application in the server context. Since the attack vector is network-based (AV:N) and does not require user interaction (UI:N), the exploit can be carried out remotely over the network.

Impact

An attacker can obtain full remote code execution (RCE) on the Ivanti CSA server, which potentially leads to system compromise, data theft, and further lateral movement in the network. The scope of the attack extends beyond the vulnerable component (S:C), and the confidentiality, integrity, and availability of the system are completely compromised.

Mitigation & patch

Ivanti CSA should be updated to version 5.0.3 or later as soon as possible. Detailed information is available in the official Ivanti security bulletin at the address indicated in the references. Until the patch is deployed, it is recommended to restrict access to the administration panel exclusively to trusted IP addresses and monitor logs for unauthorized administrative activities.

Who is affected

Ivanti Cloud Services Appliance (CSA) in all versions before 5.0.3

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Ivanti Cloud Services Appliance

    APP
    Ivanti
    < 5.0.3
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2024-47908CRITICAL9.1PL ✓same product

OS command injection w Ivanti CSA — RCE dla admina

CVE-2024-11639CRITICAL10.0PL ✓same product

Authentication bypass w panelu admina Ivanti CSA — pełny dostęp bez logowania

CVE-2024-11773CRITICAL9.1PL ✓same product

SQL injection w konsoli administracyjnej Ivanti CSA — zdalne wykonanie zapytań SQL

CVE-2024-8190HIGH7.2⚠ KEVsame product

An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before all...

CVE-2025-22460HIGH7.8same product

Default credentials in Ivanti Cloud Services Application before version 5.0.5 allows a local authenticated att...