CVE-2021-44529: Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
Other sources
Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code with limited permissions (nobody).
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-44529?
CVE-2021-44529 is considered a critical vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2021-44529?
To fix CVE-2021-44529, update the Ivanti Endpoint Manager Cloud Services Appliance to version 4.6 or later.
What types of systems are affected by CVE-2021-44529?
CVE-2021-44529 affects Ivanti Endpoint Manager Cloud Services Appliance versions up to and including 4.5 and version 4.6.
What can an attacker do with CVE-2021-44529?
An attacker can exploit CVE-2021-44529 to execute arbitrary code with limited permissions on the Ivanti EPM Cloud Services Appliance.
Is authentication required to exploit CVE-2021-44529?
No, CVE-2021-44529 can be exploited by an unauthenticated user.