logo

Multiple Vulnerabilities in Ivanti Cloud Services Application (CSA) Could Allow for Remote Code Execution

ID: cd072e2f-6b69-5b07-9832-fe5319cb5d46

STIX ID: report--cd072e2f-6b69-5b07-9832-fe5319cb5d46

Feed Name: CISecurity.org Advisories

Threat Score
75/100

Date Published: 2024-12-11

Date Updated: 2026-04-27

...
...

**Ivanti CSA vulnerabilities (pre-5.0.3):** Multiple severe flaws were disclosed in Ivanti Cloud Services Application affecting the admin web console — an authentication bypass (CVE-2024-11639) enabling unauthenticated administrative access, a command injection (CVE-2024-11772) allowing remote code execution for authenticated admins, and a SQL injection (CVE-2024-11773) permitting arbitrary SQL execution; successful exploitation could lead to full system compromise and data manipulation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.