Description
Ivanti CSA contains a path traversal vulnerability that could allow an unauthenticated attacker to access restricted functionality and exploit the RCE vulnerability, CVE-2024-8190, to compromise the system.
Remediation
Upgrade to the latest version of Ivanti CSA.
References
Security Advisory Ivanti CSA 4.6 (Cloud Services Appliance) (CVE-2024-8963)
Security Advisory Ivanti Cloud Service Appliance (CSA) (CVE-2024-8190)
Burning Zero Days: Suspected Nation-State Adversary Targets Ivanti CSA
Related Vulnerabilities
Twisted Web HTTP Server Improper Certificate Validation Vulnerability (CVE-2019-12855)
Oracle HTTP Server CVE-2018-2760 Vulnerability (CVE-2018-2760)
Python Improper Restriction of XML External Entity Reference Vulnerability (CVE-2017-9233)
phpMyFAQ Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-0788)
Jenkins Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2023-27900)