CVE-2024-11772: Command Injection
Published Dec 10, 2024
·Updated
Command injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
Affected Software
1 affected component
Ivanti Cloud Services Appliance<5.0.3
Event History
Dec 10, 2024
CVE Published
via MITRE·06:55 PM
Data Sourced
via MITRE·06:55 PM
DescriptionSeverityWeakness
Dec 11, 2024
News Published
via The Register·12:04 PM
News Published
via The Register·12:07 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-11772?
CVE-2024-11772 is considered a critical vulnerability due to its potential for remote code execution by authenticated attackers.
2
How do I fix CVE-2024-11772?
To fix CVE-2024-11772, upgrade to Ivanti Cloud Services Appliance version 5.0.3 or later immediately.
3
Who is affected by CVE-2024-11772?
CVE-2024-11772 affects all versions of Ivanti Cloud Services Appliance prior to 5.0.3 that are used with admin privileges.
4
What type of vulnerability is CVE-2024-11772?
CVE-2024-11772 is a command injection vulnerability found in the admin web console of Ivanti Cloud Services Appliance.
5
Can CVE-2024-11772 be exploited remotely?
Yes, CVE-2024-11772 can be exploited remotely by an authenticated attacker with admin privileges.