← Vulnerability feed

Vulnerability record · CVE-2024-9380 · published 8 October 2024

CVE-2024-9380: Ivanti CSA admin console OS command injection enables RCE

Ivanti · Endpoint Manager Cloud Services Appliance

Ivanti Cloud Services Appliance (CSA) before version 5.0.2 contains an OS command injection flaw in its admin web console. An attacker who already holds admin privileges can inject commands that execute on the underlying appliance, turning a management interface into a remote code execution path. It matters because the appliance sits at the network edge and CISA has flagged it as exploited in the wild.

7.2 CVSS 3.1 High CISA KEV since 9 Oct 2024 EPSS 60% · top 0.9% CWE-77 · Command injectionCWE-78 · OS command injection
7.2CVSS 3.1 base score
60%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityIt is listed in CISA KEV with known exploitation, carries a very high EPSS score, and yields remote code execution on an edge appliance, though it requires prior admin authentication.

What it is

Ivanti Cloud Services Appliance (CSA) before version 5.0.2 contains an OS command injection flaw in its admin web console. An attacker who already holds admin privileges can inject commands that execute on the underlying appliance, turning a management interface into a remote code execution path. It matters because the appliance sits at the network edge and CISA has flagged it as exploited in the wild.

Impact

An authenticated admin gains arbitrary command execution on the CSA appliance, allowing full compromise of the device and any credentials or trust relationships it holds. Because the attacker already has admin rights, the flaw escalates console access into operating-system-level control.

Attack surface

Reached over the network through the admin web console (CVSS AV:N), requiring high privileges (PR:H) and no user interaction (UI:N). The attacker must already be authenticated as an admin, so this is post-authentication rather than a pre-auth entry point.

Exploitation

CISA added it to the KEV catalog on 2024-10-09 with a remediation due date of 2024-10-30, indicating known exploitation. EPSS is very high at roughly 0.63 (99th percentile), and no ransomware campaign use is documented in the record.

What to do

  • Upgrade Ivanti CSA to 5.0.2 or later; CSA 4.6.x is end-of-life and should be removed from service or migrated to the supported 5.0.x line.
  • Restrict admin console access to trusted management networks and remove internet exposure where possible.
  • Audit and reduce the number of accounts holding CSA admin privileges, and rotate credentials for those accounts.
  • Monitor for unexpected outbound connections or process execution originating from the CSA appliance.

Detection

  • Review CSA admin console and appliance logs for unusual command execution or process spawning tied to web console activity.
  • Alert on new or unexpected outbound network connections from the CSA appliance.
  • Monitor authentication logs for admin logins from unusual source addresses or at anomalous times.
  • Hunt for indicators published in Ivanti's advisory and CISA KEV guidance for this CVE.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-9380 to the Known Exploited Vulnerabilities catalog on 9 October 2024 as "Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability". Required action: As Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line, or later, of supported solution. Federal deadline 30 October 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-9380 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-44529Ivanti EPM Cloud Services Appliance unauthenticated code injectionIvanti Endpoint Manager Cloud Services Appliance (CSA) contains a code injection flaw (CWE-94) that lets an unauthenticated remote user execute arbit…KEVEPSS 99%analysed9.1CVE-2024-8963Ivanti CSA path traversal allows unauthenticated access to restricted functionsIvanti Cloud Services Appliance (CSA) before 4.6 Patch 519 contains a path traversal flaw (CWE-22) that lets a remote, unauthenticated attacker reach…KEVEPSS 99%analysed7.2CVE-2024-9379Ivanti CSA admin console SQL injectionIvanti Cloud Services Appliance (CSA) before version 5.0.2 contains a SQL injection flaw in its admin web console (CWE-89). A remote attacker who alr…KEVEPSS 44%analysed7.2CVE-2024-9381Ivanti endpoint manager cloud services appliance path traversal vulnerabilityPath traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.EPSS 16%9.8CVE-2026-8037Progress LoadMaster API OS Command Injection RCEProgress LoadMaster (and related ADC products) contain an OS command injection flaw in multiple API command endpoints where unsanitized input is pass…KEVEPSS 77%analysed8.7CVE-2026-42271LiteLLM MCP test endpoints allow authenticated OS command injectionLiteLLM versions 1.74.2 through before 1.83.7 expose two MCP preview endpoints (POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list) th…KEVEPSS 13%analysed7.2CVE-2025-29635D-Link DIR-823X command injection in set_prohibiting handlerD-Link DIR-823X firmware (240126 and 240802) contains a command injection flaw in the /goform/set_prohibiting POST handler. An attacker who already h…KEVEPSS 88%analysed8.1CVE-2026-22719VMware Aria Operations command injection during support-assisted migrationVMware Aria Operations contains a command injection flaw (CWE-77) that an unauthenticated attacker can use to run arbitrary commands, potentially ach…KEVEPSS 18%analysed

Source: NIST National Vulnerability Database (record CVE-2024-9380), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.