CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-47908

CVSS 9.1v3.1pub. 2025-02-11upd. 2025-02-20

OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

🤖 AI Analysis
How it works

The vulnerability consists of insufficient input data validation in the administrative panel of the Ivanti CSA web application, which allows injection of malicious operating system commands (OS command injection, CWE-78). An authenticated attacker with administrator privileges can prepare an appropriate request to the web console, causing the operating system of the device to execute the provided commands in the context of the application. The attack is carried out remotely over the network, without the need for physical access to the device.

Impact

Successful exploitation of this vulnerability allows an attacker to execute code remotely (RCE) on an Ivanti CSA device, which may result in complete system takeover, data read and modification, and violation of confidentiality, integrity, and availability of the entire environment.

Mitigation & patch

Ivanti Cloud Services Appliance should be updated to version 5.0.5 or later. Detailed information is available in the manufacturer's security advisory at the address indicated in the references. As a temporary measure, it is recommended to restrict access to the administrative console only to trusted IP addresses and to apply the principle of least privilege.

Who is affected

Ivanti Cloud Services Appliance (CSA) in all versions prior to 5.0.5

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Ivanti Cloud Services Appliance

    APP
    Ivanti
    < 5.0.5
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCECommand Injection
CWE
References

Related vulnerabilities

CVE-2024-11639CRITICAL10.0PL ✓same product

Authentication bypass w panelu admina Ivanti CSA — pełny dostęp bez logowania

CVE-2024-11772CRITICAL9.1PL ✓same product

Command injection w konsoli administracyjnej Ivanti CSA umożliwia RCE

CVE-2024-11773CRITICAL9.1PL ✓same product

SQL injection w konsoli administracyjnej Ivanti CSA — zdalne wykonanie zapytań SQL

CVE-2024-8190HIGH7.2⚠ KEVsame product

An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before all...

CVE-2025-22460HIGH7.8same product

Default credentials in Ivanti Cloud Services Application before version 5.0.5 allows a local authenticated att...