First published: Wed Dec 08 2021(Updated: )
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
Credit: support@hackerone.com support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti Endpoint Manager Cloud Services Appliance | <=4.5 | |
Ivanti Endpoint Manager Cloud Services Appliance | =4.6 | |
Ivanti Endpoint Manager Cloud Services Appliance |
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-44529 is considered a critical vulnerability due to the potential for arbitrary code execution.
To fix CVE-2021-44529, update the Ivanti Endpoint Manager Cloud Services Appliance to version 4.6 or later.
CVE-2021-44529 affects Ivanti Endpoint Manager Cloud Services Appliance versions up to and including 4.5 and version 4.6.
An attacker can exploit CVE-2021-44529 to execute arbitrary code with limited permissions on the Ivanti EPM Cloud Services Appliance.
No, CVE-2021-44529 can be exploited by an unauthenticated user.