CVE-2024-47908: OS Command Injection
Published Feb 11, 2025
·Updated
OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
Affected Software
2 affected components
Ivanti CSA<5.0.5
Ivanti Cloud Services Appliance<5.0.5
Event History
Feb 11, 2025
CVE Published
via MITRE·03:18 PM
Data Sourced
via MITRE·03:18 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-47908?
The severity of CVE-2024-47908 is critical due to its potential to allow remote code execution.
2
How do I fix CVE-2024-47908?
To fix CVE-2024-47908, upgrading to Ivanti CSA version 5.0.5 or later is required.
3
Who is affected by CVE-2024-47908?
CVE-2024-47908 affects users of Ivanti CSA versions prior to 5.0.5 with admin privileges.
4
What type of vulnerability is CVE-2024-47908?
CVE-2024-47908 is classified as an OS command injection vulnerability.
5
Can CVE-2024-47908 be exploited remotely?
Yes, CVE-2024-47908 can be exploited remotely by authenticated attackers with admin privileges.