October 9, 2024 · Applied Cybernetics Group
CVE-2024-9379 — Ivanti Cloud Services Appliance (CSA)
Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability
- Added to KEV
2024-10-09- Federal due date
2024-10-30- Vendor
- Ivanti
- Product
- Cloud Services Appliance (CSA)
- EPSS
- 98.7th percentile (score 0.438, as of
2026-10-04) - NVD CVSS v3.1
- 6.5 (MEDIUM)
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2024-9379
CISA short description
Ivanti Cloud Services Appliance (CSA) contains a SQL injection vulnerability in the admin web console in versions prior to 5.0.2, which can allow a remote attacker authenticated as administrator to run arbitrary SQL statements.
Required action
As Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line, or later, of supported solution.
NVD description
SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.