Command injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
The vulnerability lies in insufficient input validation in the administration console of the Ivanti CSA web application, which is classified as command injection (CWE-77). An attacker with an administrator account can submit crafted data containing malicious system commands that will be executed by the application in the server context. Since the attack vector is network-based (AV:N) and does not require user interaction (UI:N), the exploit can be carried out remotely over the network.
An attacker can obtain full remote code execution (RCE) on the Ivanti CSA server, which potentially leads to system compromise, data theft, and further lateral movement in the network. The scope of the attack extends beyond the vulnerable component (S:C), and the confidentiality, integrity, and availability of the system are completely compromised.
Ivanti CSA should be updated to version 5.0.3 or later as soon as possible. Detailed information is available in the official Ivanti security bulletin at the address indicated in the references. Until the patch is deployed, it is recommended to restrict access to the administration panel exclusively to trusted IP addresses and monitor logs for unauthorized administrative activities.
Ivanti Cloud Services Appliance (CSA) in all versions before 5.0.3
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HIvanti Cloud Services Appliance
APPIvanti< 5.0.3
Related vulnerabilities
OS command injection w Ivanti CSA — RCE dla admina
Authentication bypass w panelu admina Ivanti CSA — pełny dostęp bez logowania
SQL injection w konsoli administracyjnej Ivanti CSA — zdalne wykonanie zapytań SQL
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before all...
Default credentials in Ivanti Cloud Services Application before version 5.0.5 allows a local authenticated att...