← Vulnerability feed

Vulnerability record · CVE-2024-9379 · published 8 October 2024

CVE-2024-9379: Ivanti CSA admin console SQL injection

Ivanti · Endpoint Manager Cloud Services Appliance

Ivanti Cloud Services Appliance (CSA) before version 5.0.2 contains a SQL injection flaw in its admin web console (CWE-89). A remote attacker who already holds admin privileges can execute arbitrary SQL statements against the appliance. Because the affected console is the management interface, successful abuse can compromise the integrity and confidentiality of the appliance's data.

7.2 CVSS 3.1 High CISA KEV since 9 Oct 2024 EPSS 44% · top 1.3% CWE-89 · SQL injection
7.2CVSS 3.1 base score
44%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw is in CISA KEV with a high EPSS score and high CVSS impact, though exploitation requires an already-authenticated admin account.

What it is

Ivanti Cloud Services Appliance (CSA) before version 5.0.2 contains a SQL injection flaw in its admin web console (CWE-89). A remote attacker who already holds admin privileges can execute arbitrary SQL statements against the appliance. Because the affected console is the management interface, successful abuse can compromise the integrity and confidentiality of the appliance's data.

Impact

An attacker with admin access gains the ability to run arbitrary SQL statements, enabling read and modification of database contents and potentially further compromise of the appliance. The CVSS vector rates confidentiality, integrity and availability impact all High.

Attack surface

Reached over the network via the CSA admin web console (AV:N, AC:L). The vector requires high privileges (PR:H) and no user interaction (UI:N), so the attacker must already be an authenticated admin.

Exploitation

CVE-2024-9379 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2024-10-09), and EPSS gives a 30-day probability of roughly 0.44 (98.7th percentile), indicating active exploitation is expected. No ransomware campaign use is documented in the record.

What to do

  • Upgrade Ivanti CSA to version 5.0.2 or later; this is the primary fix.
  • Remove CSA 4.6.x from service, as it is end-of-life and unsupported, per CISA's required action.
  • Restrict network access to the CSA admin console to trusted management networks only.
  • Audit and minimize the number of accounts holding admin privileges on CSA.
  • Monitor for unexpected SQL activity or configuration changes originating from the admin console.

Detection

  • Review CSA admin console and database logs for anomalous or unexpected SQL statements.
  • Alert on admin console logins from unusual source IPs or outside normal administrative hours.
  • Monitor for configuration or data changes on the appliance that do not match approved change records.
  • Correlate CSA admin activity with outbound network connections that could indicate post-exploitation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-9379 to the Known Exploited Vulnerabilities catalog on 9 October 2024 as "Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability". Required action: As Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line, or later, of supported solution. Federal deadline 30 October 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-9379 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-44529Ivanti EPM Cloud Services Appliance unauthenticated code injectionIvanti Endpoint Manager Cloud Services Appliance (CSA) contains a code injection flaw (CWE-94) that lets an unauthenticated remote user execute arbit…KEVEPSS 99%analysed9.1CVE-2024-8963Ivanti CSA path traversal allows unauthenticated access to restricted functionsIvanti Cloud Services Appliance (CSA) before 4.6 Patch 519 contains a path traversal flaw (CWE-22) that lets a remote, unauthenticated attacker reach…KEVEPSS 99%analysed7.2CVE-2024-9380Ivanti CSA admin console OS command injection enables RCEIvanti Cloud Services Appliance (CSA) before version 5.0.2 contains an OS command injection flaw in its admin web console. An attacker who already ho…KEVEPSS 60%analysed7.2CVE-2024-9381Ivanti endpoint manager cloud services appliance path traversal vulnerabilityPath traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.EPSS 16%9.8CVE-2026-76461Cisco AsyncOS email parsing SQL injection allows root command executionCisco AsyncOS Software for Cisco Secure Email Gateway fails to properly validate email parsing input, allowing crafted email messages containing mali…KEVEPSS 28%analysed9.3CVE-2026-9586Sangoma Switchvox unauthenticated SQL injection in /pa endpointSangoma Switchvox SMB Edition 8.3 (104997) fails to sanitize the PhoneIP value from XML content beginning with <PolycomIPPhone> before concatenating …KEVEPSS 19%analysed10.0CVE-2026-72898Metabase unauthenticated SQL injection in reset_password endpointMetabase exposes a database endpoint, '/reset_password', that fails to neutralize attacker-supplied SQL, allowing arbitrary SQL injection. Because th…KEVEPSS 19%analysed5.9CVE-2026-60137WordPress WP_Query author__not_in SQL injectionWordPress core fails to properly sanitise the author__not_in parameter of WP_Query in versions before 6.8.6, 6.9.5 and 7.0.2, allowing SQL injection …KEVEPSS 5.9%analysed

Source: NIST National Vulnerability Database (record CVE-2024-9379), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.