CVE-2024-11771: Path Traversal
Published Feb 11, 2025
·Updated
Path traversal in Ivanti CSA before version 5.0.5 allows a remote unauthenticated attacker to access restricted functionality.
Affected Software
2 affected components
Ivanti Cloud Security Agent<5.0.5
Ivanti Cloud Services Appliance<5.0.5
Event History
Feb 11, 2025
CVE Published
via MITRE·03:19 PM
Data Sourced
via MITRE·03:19 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-11771?
CVE-2024-11771 is considered a critical vulnerability due to its potential for remote unauthorized access.
2
How do I fix CVE-2024-11771?
To fix CVE-2024-11771, upgrade Ivanti Cloud Security Agent to version 5.0.5 or later immediately.
3
Who is affected by CVE-2024-11771?
CVE-2024-11771 affects all versions of Ivanti Cloud Security Agent prior to 5.0.5.
4
What type of attack does CVE-2024-11771 allow?
CVE-2024-11771 allows remote unauthenticated attackers to exploit path traversal vulnerabilities.
5
What functionality could be accessed due to CVE-2024-11771?
CVE-2024-11771 enables remote attackers to access restricted functionalities within the Ivanti Cloud Security Agent.