CVE-2024-9379Medium· 6.5▾ Midnight⚠ Exploited in the wild0dayPoC availableSQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 35.8 · likelihood 8.8 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Oct 30, 2024
Last analysed / modified upstream
44%
Added to the CISA catalog on Oct 9, 2024. Federal remediation due Oct 30, 2024. View catalog ↗
SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
endpoint_manager_cloud_services_appliance < 5.0.2Upgrade past the affected range:
endpoint_manager_cloud_services_appliance 5.0.2Connected by shared product, vendor, weakness, or advisory.
CVE-2021-44529Critical· 9.8A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
CVE-2017-18362Critical· 9.8ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database
CVE-2019-7481High· 7.5Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources
CVE-2025-0282Critical· 9.0A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve…
CVE-2023-46805High· 8.2An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.
CVE-2020-29574Critical· 9.8An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.