CVE-2024-8963: Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability
Ivanti Cloud Services Appliance (CSA) contains a path traversal vulnerability that could allow a remote, unauthenticated attacker to access restricted functionality. If CVE-2024-8963 is used in conjunction with CVE-2024-8190, an attacker could bypass admin authentication and execute arbitrary commands on the appliance.
Other sources
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ivanti Cloud Services Appliance (CSA)to a version that resolves this vulnerability.Fixed in 5.0.x - Upgrade
Upgrade
Ivanti Cloud Services Appliance (CSA) 4.6to a version that resolves this vulnerability.Patch 4.6 Patch 519 - Remove
Remove
Ivanti Cloud Services Appliance (CSA) 4.6.xfrom your environment.Remove CSA 4.6.x from service because it has reached End-of-Life.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-8963?
CVE-2024-8963 is considered a critical vulnerability due to its potential to allow remote, unauthenticated access to restricted functionality.
How do I fix CVE-2024-8963?
To fix CVE-2024-8963, update the Ivanti Cloud Services Appliance to the latest patched version provided by Ivanti.
Which versions of the Ivanti Cloud Services Appliance are affected by CVE-2024-8963?
CVE-2024-8963 affects Ivanti Endpoint Manager Cloud Services Appliance versions 4.6, 4.6-patch_512, and 4.6-patch_518.
What could an attacker achieve by exploiting CVE-2024-8963?
An attacker exploiting CVE-2024-8963 could potentially access restricted functionalities and, when combined with CVE-2024-8190, bypass authentication to execute higher-level privileges.
Is there any indication of active exploitation of CVE-2024-8963?
Yes, there are reports suggesting that CVE-2024-8963 has been actively exploited in the wild.