Three more vulns spotted in Ivanti CSA, all critical, one 10/10
ID: 4436c82a-5742-5cba-9466-bac8e41ee8ba
STIX ID: report--4436c82a-5742-5cba-9466-bac8e41ee8ba
Feed Name: The Register (Security)
Ivanti issued an advisory for three critical vulnerabilities in its Cloud Services Application (CSA): CVE-2024-11639 (authentication bypass, CVSS 10), CVE-2024-11772 (command injection allowing remote code execution with admin privileges), and CVE-2024-11773 (SQL injection allowing arbitrary SQL by admin users). All affect CSA versions 5.0.2 and earlier and are fixed in 5.0.3; CrowdStrike reported the issues and Ivanti reported no known customer exploitation prior to public disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
