Search Results (7 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-8190 1 Ivanti 2 Cloud Services Appliance, Endpoint Manager Cloud Services Appliance 2025-10-24 7.2 High
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.
CVE-2025-22460 1 Ivanti 1 Cloud Services Appliance 2025-07-16 7.8 High
Default credentials in Ivanti Cloud Services Application before version 5.0.5 allows a local authenticated attacker to escalate their privileges.
CVE-2024-11771 1 Ivanti 1 Cloud Services Appliance 2025-07-14 5.3 Medium
Path traversal in Ivanti CSA before version 5.0.5 allows a remote unauthenticated attacker to access restricted functionality.
CVE-2024-47908 1 Ivanti 1 Cloud Services Appliance 2025-02-20 9.1 Critical
OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE-2024-11773 1 Ivanti 1 Cloud Services Appliance 2025-01-17 9.1 Critical
SQL injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
CVE-2024-11772 1 Ivanti 1 Cloud Services Appliance 2025-01-17 9.1 Critical
Command injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE-2024-11639 1 Ivanti 1 Cloud Services Appliance 2025-01-17 10 Critical
An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access