Vulnerability record · CVE-2021-44529 · published 8 December 2021
CVE-2021-44529: Ivanti EPM Cloud Services Appliance unauthenticated code injection
Ivanti · Endpoint Manager Cloud Services Appliance
Ivanti Endpoint Manager Cloud Services Appliance (CSA) contains a code injection flaw (CWE-94) that lets an unauthenticated remote user execute arbitrary code. It carries a critical CVSS 3.1 score of 9.8 and is listed in CISA's KEV catalog, so it is a high-value target for defenders.
Description
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, unauthenticated remote code execution, KEV listing with known ransomware use, and near-maximum EPSS make this an urgent patch.
What it is
Ivanti Endpoint Manager Cloud Services Appliance (CSA) contains a code injection flaw (CWE-94) that lets an unauthenticated remote user execute arbitrary code. It carries a critical CVSS 3.1 score of 9.8 and is listed in CISA's KEV catalog, so it is a high-value target for defenders.
Impact
An attacker gains remote code execution on the CSA, though the description states execution occurs with limited permissions as the 'nobody' user. That still allows code execution on an internet-facing appliance, which can be a foothold for further compromise.
Attack surface
Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The flaw is in the CSA itself, so any exposed instance is directly at risk.
Exploitation
CISA added it to KEV on 2024-03-25 with a 2024-04-15 remediation due date and flags known ransomware campaign use; EPSS 30-day probability is 0.99105 (99.9th percentile). Public exploit references exist on Packet Storm, indicating active exploitation.
What to do
- Apply the vendor patch or mitigation from Ivanti advisory SA-2021-12-02 immediately.
- If no patch can be applied, discontinue use of the CSA or isolate it from untrusted networks per CISA guidance.
- Restrict network access to the CSA management interface to trusted hosts only.
- Monitor for and investigate any signs of compromise on CSA hosts, given known ransomware use.
- Verify the CSA is not directly internet-exposed and remove unnecessary exposure.
Detection
- Hunt for unexpected processes or command execution on CSA hosts, especially running as the 'nobody' user.
- Review CSA and web server logs for anomalous requests or injection patterns targeting the appliance.
- Monitor network egress from CSA hosts for command-and-control or lateral movement activity.
- Alert on any new or unusual files, scripts, or scheduled tasks created on the CSA.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-44529 to the Known Exploited Vulnerabilities catalog on 25 March 2024 as "Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability ". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 15 April 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/166383/Ivanti-Endpoint-Manager-CSA-4.5-4.6-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/170590/Ivanti-Cloud-Services-Appliance-CSA-Command-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| https://forums.ivanti.com/s/article/SA-2021-12-02 | MitigationPatchVendor Advisory |
| http://packetstormsecurity.com/files/166383/Ivanti-Endpoint-Manager-CSA-4.5-4.6-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/170590/Ivanti-Cloud-Services-Appliance-CSA-Command-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| https://forums.ivanti.com/s/article/SA-2021-12-02 | MitigationPatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-44529 | US Government Resource |
Track CVE-2021-44529 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-44529), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.