CISA Known Exploited Vulnerability (KEV)
Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability
September 19, 2024
October 10, 2024
As Ivanti CSA has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line of supported solutions, as future vulnerabilities on the 4.6.x version of CSA are unlikely to receive security updates.
Description
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.
Weakness Enumeration
CWE-ID | CWE Name |
---|---|
CWE-22 |
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) |