logo

Ivanti warns of maximum severity CSA auth bypass vulnerability

ID: 7ee30830-acd7-54a2-97eb-f427d80fbb17

STIX ID: report--7ee30830-acd7-54a2-97eb-f427d80fbb17

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-12-10

Date Updated: 2026-03-27

Author: Sergiu Gatlan

...
...

Ivanti disclosed CVE-2024-11639, a critical authentication-bypass vulnerability in Cloud Services Appliance (CSA) affecting versions 5.0.2 and earlier that can grant remote attackers administrative privileges without authentication; Ivanti recommends upgrading to CSA 5.0.3. The advisory states there is no known public exploitation of this CVE, while also noting several other Ivanti products received patches and recounting prior zero-day exploitation campaigns against Ivanti appliances earlier in the year.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.