CVE-2024-8963
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.
Published:Sep 19, 2024
Last Modified:Oct 24, 2025
EPS:Sep 19, 2024
EPSS Score:0.94305
CVSS Score:9.4
CISA Notification
Description
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.
Required Action:
As Ivanti CSA has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line of supported solutions, as future vulnerabilities on the 4.6.x version of CSA are unlikely to receive security updates.
Notes:
No extra notes provided.
Due Date
Oct 10, 2024
701 days ago
Alert Date
Sep 19, 2024
722 days ago
Affected Products
Vendor
Product
Action
Vendor
Ivanti
Product
Endpoint Manager Cloud Services Appliance
Ivanti
Endpoint Manager Cloud Services Appliance
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
