📦

endpoint_manager_cloud_services_appliance

Vendor: ivanti

Actively Exploited 4 CISA KEV List
PoC / Exploits 2 Code Available
Total RCEs 2 Remote Access
Total CVEs 5 Total Indexed
Avg. EPSS 63.87% Exploit Prob.
Latest CVE CVE-2024-9381 Oct 08

Security Vulnerability Index

Page 1 / 1
7.2 CVSS

Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.

EPSS: 15.55%
7.2 CVSS

An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution.

EPSS: 62.78%
6.5 CVSS

SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.

EPSS: 43.36%
Critical Target
9.4 CVSS
CVE-2024-8963
Exploit Found

Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.

EPSS: 98.56%
Critical Target
9.8 CVSS
CVE-2021-44529
RCE Exploit Found

A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).

EPSS: 99.11%