Vulnerability Intelligence Report
Ivanti Cloud Services Appliance OS Command Injection Vulnerability
CVE-2024-8190
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.
CISA KEV
SSVC: Active Exploitation
CVSS Base Score
7.2
HIGH
Exploitability:1.3
Impact Score:5.9
EPSS Probability:88.95%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-78 ↗CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Ivanti | CSA (Cloud Services Appliance) | 4.6 Patch 519 (unaffected), 5.0 (unaffected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Ivanti · Vendor · USA |
| Reserved | 2024-08-26T19:12:19 |
| Published | 2024-09-10T20:33:44 |
| Last Updated | 2025-10-21T22:55:44 |
Community Chatter & Buzz