claytonvantol.us
SESSION: secure TLS: 1.3 PID: 1337

clayton@site:~/news$ cat cve-2024-9379-ivanti-cloud-services-appliance-csa.log

CVE-2024-9379 — Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability

2024-10-09 • CISA Known Exploited Vulnerability


[event] Ivanti Cloud Services Appliance (CSA) contains a SQL injection vulnerability in the admin web console in versions prior to 5.0.2, which can allow a remote attacker authenticated as administrator to run arbitrary SQL statements.

> AFFECTED SOFTWARE

Field Value
Vendor Ivanti
Product Cloud Services Appliance (CSA)
CWE CWE-89
CVE ID CVE-2024-9379
Date Added 2024-10-09
Due Date 2024-10-30
Ransomware Campaign Unknown

> MITIGATION

As Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line, or later, of supported solution.

Due Date: 2024-10-30

> REFERENCES


← back to terminal

UPTIME: 1337d v2.0.1 privacy LAST LOGIN: 2026-05-30 20:36:09 UTC