OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
The vulnerability consists of insufficient input data validation in the administrative panel of the Ivanti CSA web application, which allows injection of malicious operating system commands (OS command injection, CWE-78). An authenticated attacker with administrator privileges can prepare an appropriate request to the web console, causing the operating system of the device to execute the provided commands in the context of the application. The attack is carried out remotely over the network, without the need for physical access to the device.
Successful exploitation of this vulnerability allows an attacker to execute code remotely (RCE) on an Ivanti CSA device, which may result in complete system takeover, data read and modification, and violation of confidentiality, integrity, and availability of the entire environment.
Ivanti Cloud Services Appliance should be updated to version 5.0.5 or later. Detailed information is available in the manufacturer's security advisory at the address indicated in the references. As a temporary measure, it is recommended to restrict access to the administrative console only to trusted IP addresses and to apply the principle of least privilege.
Ivanti Cloud Services Appliance (CSA) in all versions prior to 5.0.5
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HIvanti Cloud Services Appliance
APPIvanti< 5.0.5
Related vulnerabilities
Authentication bypass w panelu admina Ivanti CSA — pełny dostęp bez logowania
Command injection w konsoli administracyjnej Ivanti CSA umożliwia RCE
SQL injection w konsoli administracyjnej Ivanti CSA — zdalne wykonanie zapytań SQL
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before all...
Default credentials in Ivanti Cloud Services Application before version 5.0.5 allows a local authenticated att...