Vulnerability record · CVE-2024-9379 · published 8 October 2024
CVE-2024-9379: Ivanti CSA admin console SQL injection
Ivanti · Endpoint Manager Cloud Services Appliance
Ivanti Cloud Services Appliance (CSA) before version 5.0.2 contains a SQL injection flaw in its admin web console (CWE-89). A remote attacker who already holds admin privileges can execute arbitrary SQL statements against the appliance. Because the affected console is the management interface, successful abuse can compromise the integrity and confidentiality of the appliance's data.
Description
SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is in CISA KEV with a high EPSS score and high CVSS impact, though exploitation requires an already-authenticated admin account.
What it is
Ivanti Cloud Services Appliance (CSA) before version 5.0.2 contains a SQL injection flaw in its admin web console (CWE-89). A remote attacker who already holds admin privileges can execute arbitrary SQL statements against the appliance. Because the affected console is the management interface, successful abuse can compromise the integrity and confidentiality of the appliance's data.
Impact
An attacker with admin access gains the ability to run arbitrary SQL statements, enabling read and modification of database contents and potentially further compromise of the appliance. The CVSS vector rates confidentiality, integrity and availability impact all High.
Attack surface
Reached over the network via the CSA admin web console (AV:N, AC:L). The vector requires high privileges (PR:H) and no user interaction (UI:N), so the attacker must already be an authenticated admin.
Exploitation
CVE-2024-9379 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2024-10-09), and EPSS gives a 30-day probability of roughly 0.44 (98.7th percentile), indicating active exploitation is expected. No ransomware campaign use is documented in the record.
What to do
- Upgrade Ivanti CSA to version 5.0.2 or later; this is the primary fix.
- Remove CSA 4.6.x from service, as it is end-of-life and unsupported, per CISA's required action.
- Restrict network access to the CSA admin console to trusted management networks only.
- Audit and minimize the number of accounts holding admin privileges on CSA.
- Monitor for unexpected SQL activity or configuration changes originating from the admin console.
Detection
- Review CSA admin console and database logs for anomalous or unexpected SQL statements.
- Alert on admin console logins from unusual source IPs or outside normal administrative hours.
- Monitor for configuration or data changes on the appliance that do not match approved change records.
- Correlate CSA admin activity with outbound network connections that could indicate post-exploitation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-9379 to the Known Exploited Vulnerabilities catalog on 9 October 2024 as "Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability". Required action: As Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line, or later, of supported solution. Federal deadline 30 October 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-9379 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-9379), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.