Ivanti Cloud Services Appliance
cpe:2.3:a:ivanti:cloud_services_appliance:*:*:*:*:*:*:*
- 4.6
- 4.6:patch_512
This vulnerability is being actively exploited in the wild.
A path traversal vulnerability has been identified in Ivanti Cloud Services Appliance (CSA) versions 4.6 prior to Patch 519. This vulnerability allows remote, unauthenticated attackers to access restricted functionality. The issue was inadvertently addressed in Patch 519, released on September 10, 2024. However, since Ivanti CSA 4.6 has reached end-of-life and will not receive further updates, users are advised to upgrade to Ivanti CSA 5.0.
Exploitation of this vulnerability could lead to unauthorized access to restricted functionality within the Ivanti Cloud Services Appliance.
Users are strongly advised to upgrade to Ivanti Cloud Services Appliance 5.0. For those on Ivanti CSA 4.6 Patch 518, Patch 519 is available. However, as version 4.6 has reached end-of-life, the recommended path is to upgrade to version 5.0.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.