Vulnerability record · CVE-2024-9380 · published 8 October 2024
CVE-2024-9380: Ivanti CSA admin console OS command injection enables RCE
Ivanti · Endpoint Manager Cloud Services Appliance
Ivanti Cloud Services Appliance (CSA) before version 5.0.2 contains an OS command injection flaw in its admin web console. An attacker who already holds admin privileges can inject commands that execute on the underlying appliance, turning a management interface into a remote code execution path. It matters because the appliance sits at the network edge and CISA has flagged it as exploited in the wild.
Description
An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is listed in CISA KEV with known exploitation, carries a very high EPSS score, and yields remote code execution on an edge appliance, though it requires prior admin authentication.
What it is
Ivanti Cloud Services Appliance (CSA) before version 5.0.2 contains an OS command injection flaw in its admin web console. An attacker who already holds admin privileges can inject commands that execute on the underlying appliance, turning a management interface into a remote code execution path. It matters because the appliance sits at the network edge and CISA has flagged it as exploited in the wild.
Impact
An authenticated admin gains arbitrary command execution on the CSA appliance, allowing full compromise of the device and any credentials or trust relationships it holds. Because the attacker already has admin rights, the flaw escalates console access into operating-system-level control.
Attack surface
Reached over the network through the admin web console (CVSS AV:N), requiring high privileges (PR:H) and no user interaction (UI:N). The attacker must already be authenticated as an admin, so this is post-authentication rather than a pre-auth entry point.
Exploitation
CISA added it to the KEV catalog on 2024-10-09 with a remediation due date of 2024-10-30, indicating known exploitation. EPSS is very high at roughly 0.63 (99th percentile), and no ransomware campaign use is documented in the record.
What to do
- Upgrade Ivanti CSA to 5.0.2 or later; CSA 4.6.x is end-of-life and should be removed from service or migrated to the supported 5.0.x line.
- Restrict admin console access to trusted management networks and remove internet exposure where possible.
- Audit and reduce the number of accounts holding CSA admin privileges, and rotate credentials for those accounts.
- Monitor for unexpected outbound connections or process execution originating from the CSA appliance.
Detection
- Review CSA admin console and appliance logs for unusual command execution or process spawning tied to web console activity.
- Alert on new or unexpected outbound network connections from the CSA appliance.
- Monitor authentication logs for admin logins from unusual source addresses or at anomalous times.
- Hunt for indicators published in Ivanti's advisory and CISA KEV guidance for this CVE.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-9380 to the Known Exploited Vulnerabilities catalog on 9 October 2024 as "Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability". Required action: As Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line, or later, of supported solution. Federal deadline 30 October 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-9380 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-9380), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.