CyberzSOC

Publication detail
← Back to advisories & guidance

2024-119: Critical Vulnerability in Ivanti Products ↗ source

December 11, 2024 CERT-EU Advisory

Summary

These flaws could allow attackers to escalate privileges or execute arbitrary code [1,2]. The vulnerability CVE-2024-11639, with a CVSS score of 10.0, is an authentication bypass in the CSA admin web console permitting remote unauthenticated attackers to gain administrative The vulnerability CVE-2024-11772, with a CVSS score of 9.1, is a command injection in the CSA admin web console allowing remote authenticated attackers with admin privileges to achieve The vulnerability CVE-2024-11773, with a CVSS score of 9.1, is an SQL injection in the CSA admin web console enabling remote authenticated attackers with admin privileges to execute The vulnerability CVE-2024-11633, with a CVSS score of 9.1, is an argument injection in Connect Secure that allows remote authenticated attackers with admin privileges to achieve remote The vulnerability CVE-2024-11634, with a CVSS score of 9.1, is a command injection in Connect Secure and Policy Secure permitting remote authenticated attackers with admin privileges to achieve remote code execution. The vulnerability CVE-2024-8540, with a CVSS score of 8.8, is an insecure permissions issue in Sentry allowing local authenticated attackers to modify sensitive application components.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-11639 10.0 Critical Ivanti Cloud Services Application An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access
CVE-2024-11633 9.1 Critical Ivanti Connect Secure Argument injection in Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker with admin privileges to achieve remote co…
CVE-2024-11634 9.1 Critical Ivanti Connect Secure Command injection in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated att…
CVE-2024-11772 9.1 Critical Ivanti Cloud Services Application Command injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to achieve…
CVE-2024-11773 9.1 Critical Ivanti Cloud Services Application SQL injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to run arbitra…
CVE-2024-8540 8.8 High Ivanti Sentry Insecure permissions in Ivanti Sentry before versions 9.20.2 and 10.0.2 or 10.1.0 allow a local authenticated attacker to modify sensitive applicatio…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.