CVE-2024-11773: SQL Injection
Published Dec 10, 2024
·Updated
SQL injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
Affected Software
1 affected component
Ivanti Cloud Services Appliance<5.0.3
Event History
Dec 10, 2024
CVE Published
via MITRE·06:56 PM
Data Sourced
via MITRE·06:56 PM
DescriptionSeverityWeakness
Dec 11, 2024
News Published
via The Register·12:04 PM
News Published
via The Register·12:07 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-11773?
CVE-2024-11773 has a critical severity rating due to its potential for remote exploitation and SQL injection.
2
How do I fix CVE-2024-11773?
To fix CVE-2024-11773, upgrade to Ivanti Cloud Service Appliance version 5.0.3 or later.
3
Who is affected by CVE-2024-11773?
CVE-2024-11773 affects remote authenticated users with admin privileges on Ivanti Cloud Services Appliance versions prior to 5.0.3.
4
What is the impact of CVE-2024-11773?
The impact of CVE-2024-11773 allows an authenticated attacker to execute arbitrary SQL statements, potentially compromising the database.
5
Is CVE-2024-11773 publicly disclosed?
Yes, CVE-2024-11773 has been publicly disclosed, and users are advised to take immediate action to mitigate the risk.