Lucene search

K
cveIvantiCVE-2024-8963
HistorySep 19, 2024 - 6:15 p.m.

CVE-2024-8963

2024-09-1918:15:10
CWE-22
ivanti
web.nvd.nist.gov
55
In Wild
path traversal
ivanti csa
remote attacker

CVSS3

9.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

AI Score

7.2

Confidence

Low

EPSS

0.31

Percentile

97.0%

Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.

Affected configurations

Nvd
Node
ivantiendpoint_manager_cloud_services_applianceMatch4.6-
OR
ivantiendpoint_manager_cloud_services_applianceMatch4.6patch_512
OR
ivantiendpoint_manager_cloud_services_applianceMatch4.6patch_518
VendorProductVersionCPE
ivantiendpoint_manager_cloud_services_appliance4.6cpe:2.3:a:ivanti:endpoint_manager_cloud_services_appliance:4.6:-:*:*:*:*:*:*
ivantiendpoint_manager_cloud_services_appliance4.6cpe:2.3:a:ivanti:endpoint_manager_cloud_services_appliance:4.6:patch_512:*:*:*:*:*:*
ivantiendpoint_manager_cloud_services_appliance4.6cpe:2.3:a:ivanti:endpoint_manager_cloud_services_appliance:4.6:patch_518:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "affected",
    "product": "CSA (Cloud Services Appliance)",
    "vendor": "Ivanti",
    "versions": [
      {
        "status": "unaffected",
        "version": "4.6 Patch 519",
        "versionType": "custom"
      },
      {
        "status": "unaffected",
        "version": "5.0",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

9.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

AI Score

7.2

Confidence

Low

EPSS

0.31

Percentile

97.0%