CVE-2024-9379 is a critical SQL injection vulnerability in the admin web console of Ivanti Cloud Services Appliance (CSA) versions prior to 5.0.2. This flaw allows a remote, authenticated attacker with administrative privileges to execute arbitrary SQL statements. With a CVSS score of 7.2 (High) and a FAUCET Risk Score of 100/100, its impact is severe, enabling full compromise of confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog, and has garnered significant community discussion and media coverage, despite no public exploit code being available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.0.2CPE matchmatch criteria | cpe:2.3:a:ivanti:endpoint_manager_cloud_services_appliance:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.