Ivanti's Cloud Service Appliance Attacked via Second Vuln
ID: 1c624aad-2dd1-58a2-a5ea-cde7652c1c69
STIX ID: report--1c624aad-2dd1-58a2-a5ea-cde7652c1c69
Feed Name: Dark Reading
Date Published: 2024-09-20
Date Updated: 2026-04-21
Author: Kristina Beek, Associate Editor, Dark Reading
Ivanti disclosed a critical path traversal vulnerability in Cloud Services Appliance (CVE-2024-8963, CVSS 9.4) being exploited in the wild and chained with a separate OS command injection flaw (CVE-2024-8190) to bypass admin authentication and potentially achieve remote code execution; customers are advised to upgrade to CSA 5.0 (or apply patch 519), verify dual-homed configurations and administrator accounts, and review EDR alerts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
