CVE CVE

CVE-2021-44529

CISA Known Exploited Vulnerability (KEV)

Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability

March 25, 2024

April 15, 2024

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).

Weakness Enumeration

CWE-ID CWE Name

CWE-94
Improper Control of Generation of Code (‘Code Injection’)

Details

Source:
NVD
Published:
Updated:

Risk information

CVSS v3

Base score:
9.8
Severity:

CRITICAL

Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2

Base score:
7.5
Severity:

HIGH

Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P