CVE-2024-11639: Critical severity ivanti cloud service appliances vulnerability
Published Dec 10, 2024
·Updated
An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access
Affected Software
1 affected component
Ivanti Cloud Services Appliance<5.0.3
Event History
Dec 10, 2024
CVE Published
via MITRE·06:54 PM
Data Sourced
via MITRE·06:54 PM
DescriptionSeverityWeakness
News Published
via BleepingComputer·07:40 PM
News Published
via BleepingComputer·07:41 PM
Dec 11, 2024
News Published
via The Register·12:04 PM
News Published
via The Register·12:07 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-11639?
CVE-2024-11639 is considered a critical vulnerability due to its potential for unauthorized administrative access.
2
How do I fix CVE-2024-11639?
To fix CVE-2024-11639, update Ivanti Cloud Service Appliance to version 5.0.3 or later.
3
Who is affected by CVE-2024-11639?
CVE-2024-11639 affects all versions of Ivanti Cloud Service Appliance prior to 5.0.3.
4
What type of vulnerability is CVE-2024-11639?
CVE-2024-11639 is categorized as an authentication bypass vulnerability.
5
Can CVE-2024-11639 be exploited remotely?
Yes, CVE-2024-11639 can be exploited by remote unauthenticated attackers.