CVE-2024-9381: Path Traversal
Published Oct 8, 2024
·Updated
Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.
Affected Software
1 affected component
Ivanti Endpoint Manager Cloud Services Appliance<5.0.2
Event History
Oct 8, 2024
News Published
via BleepingComputer·04:05 PM
News Published
via BleepingComputer·04:06 PM
CVE Published
via MITRE·04:25 PM
Data Sourced
via MITRE·04:25 PM
DescriptionSeverityWeakness
Oct 10, 2024
News Published
via The Register·01:34 PM
News Published
via The Register·01:38 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-9381?
CVE-2024-9381 has a high severity rating due to its potential for path traversal vulnerabilities that allow unauthorized access.
2
How do I fix CVE-2024-9381?
To fix CVE-2024-9381, upgrade to Ivanti CSA version 5.0.2 or later as it addresses this vulnerability.
3
Who is affected by CVE-2024-9381?
CVE-2024-9381 affects users of Ivanti Endpoint Manager Cloud Services Appliance versions before 5.0.2.
4
What type of attack can exploit CVE-2024-9381?
CVE-2024-9381 can be exploited by a remote authenticated attacker with admin privileges who uses path traversal techniques.
5
Is there a workaround for CVE-2024-9381 before applying the fix?
There are no recommended workarounds for CVE-2024-9381, so upgrading to the latest version is essential.