CVE-2024-9380 Details
Description
An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution.
A command injection vulnerability has been identified in the admin web console of Ivanti Cloud Services Appliance (CSA) versions prior to 5.0.2. This vulnerability allows remote authenticated attackers with admin privileges to execute arbitrary commands on the underlying operating system, potentially leading to unauthorized access or manipulation of system resources.
Users are advised to upgrade to Ivanti Cloud Services Appliance version 5.0.2. Instructions for downloading this version are available in the Ivanti Cloud Services Application 5.0.2 Download Release Notes Patch History.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 10, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-9380 | CISA-ADP | US Government Resource |
| https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-CSA-Cloud-Services-Appliance-CVE-2024-9379-CVE-2024-9380-CVE-2024-9381 | ivanti | Vendor Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability | Oct 9, 2024 | Oct 30, 2024 | As Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line, or later, of supported solution. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | ivanti |
Affected Products
| Product | Versions |
|---|---|
| ivanti endpoint manager cloud services appliance | < 5.0.2 |
CPE
Remediation
| |
Change History
9 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | ivanti |
| Oct 24, 2025 | Modified Analysis | [email protected] |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 10, 2024 | Initial Analysis | [email protected] |
| Oct 10, 2024 | CVE CISA KEV Update | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Oct 8, 2024 | New CVE Received | ivanti |