CVE-2024-9380

Published Oct 8, 2024

Last updated 9 months ago

Overview

Description
An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution.
Source
3c1d8aa1-5a33-4ea4-8992-aadd6440af75
NVD status
Analyzed
Products
endpoint_manager_cloud_services_appliance

Risk scores

CVSS 3.1

Type
Primary
Base score
7.2
Impact score
5.9
Exploitability score
1.2
Vector string
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability
Exploit added on
Oct 9, 2024
Exploit action due
Oct 30, 2024
Required action
As Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line, or later, of supported solution.

Weaknesses

3c1d8aa1-5a33-4ea4-8992-aadd6440af75
CWE-77
nvd@nist.gov
CWE-78

Social media

Hype score
Not currently trending
  1. Zero-days no Ivanti CSA (CVE-2024-8963, CVE-2024-9380, CVE-2024-8190) foram usados contra governos e mídias na França; exploração incluía bypass de autenticação e execução remota via API de gerenciamento.

    @hashtagsec

    12 Jul 2025

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2024-9380: An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution. https://t.co/tWJMphiPsb

    @ZeroDayFacts

    6 Jul 2025

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Chinese Hackers Exploit Ivanti CSA Zero-Days in Attacks on French Government, Telecoms. CVE-2024-8963, CVE-2024-9380, and CVE-2024-8190, https://t.co/aNuokthH1l

    @freedomhack101

    5 Jul 2025

    96 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 中国関連の脅威主体HoukenがIvanti Cloud Service Appliance (CSA)のゼロデイ脆弱性 (CVE-2024-8190, CVE-2024-8963, CVE-2024-9380)を悪用し、Linuxルートキットをデプロイ。フランス国家情報システムセキュリティ庁(ANSSI)報告。初期

    @__kokumoto

    2 Jul 2025

    1875 Impressions

    2 Retweets

    8 Likes

    2 Bookmarks

    0 Replies

    1 Quote

  5. This week, @CISAgov shared a writeup on the exploitation of CVE-2024-8963, an admin bypass vulnerability; CVE-2024-9379, a SQLi vulnerability; and CVE-2024-8190 and CVE-2024-9380, RCE vulnerabilities in #Ivanti CSA: https://t.co/2OW61ExzhC. ➡️ Ivanti CVE-2024-8963 has been… http

    @Horizon3ai

    24 Jan 2025

    10 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Cyberattackers are exploiting critical Ivanti CSA vulnerabilities (CVE-2024-8963, CVE-2024-9379, CVE-2024-8190, CVE-2024-9380) for admin bypass and remote code execution. Stay vigilant! ⚠️ #Ivanti #CISA #USA link: https://t.co/XTjLTwDCfM https://t.co/zpLdyydE69

    @TweetThreatNews

    23 Jan 2025

    34 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  7. #threatreport #HighCompleteness Threat Actors Chained Vulnerabilities in Ivanti Cloud Service Applications | 22-01-2025 Source: https://t.co/ndj3LPe8KK Key details below ↓ 💀Threats: Landesk_tool, Timestomp_technique, 🔓CVEs: CVE-2024-9380… https://t.co/4mHKdAY3vD https://t.co/

    @rst_cloud

    23 Jan 2025

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨 CISA and FBI warn of active exploitation of four critical vulnerabilities in Ivanti Cloud Service Appliances (CVE-2024-8963, CVE-2024-9379, CVE-2024-8190, CVE-2024-9380). Stay updated! 🔒 #Ivanti #USA #CyberAlert link: https://t.co/ofFIUEQzPv https://t.co/L8MF8545L9

    @TweetThreatNews

    23 Jan 2025

    42 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. CVE-2024-9380 alert 🚨 Ivanti CSA OS Command Injection Vulnerability : (CVSS score: 7.2/10) Update to version 5.0.2 or later to prevent authenticated admins from executing remote code. The vulnerability is actively exploited in the wild. Our customers assets are protected. 🦉 h

    @Patrowl_io

    23 Oct 2024

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. CVE-2024-43573 is getting exploited #inthewild. Find out more at https://t.co/iXgTYADn4B CVE-2024-43572 is getting exploited #inthewild. Find out more at https://t.co/3fNkZBuraP CVE-2024-9380 is getting exploited #inthewild. Find out more at https://t.co/Ibnt21MaDk

    @inthewildio

    23 Oct 2024

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations