vulnerability
Ivanti Cloud Services Application: CVE-2024-11772: Improper Neutralization of Special Elements used in a Command
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 8 | (AV:N/AC:L/Au:M/C:C/I:C/A:C) | Dec 10, 2024 | Jun 30, 2025 | Jul 11, 2025 |
Severity
8
CVSS
(AV:N/AC:L/Au:M/C:C/I:C/A:C)
Published
Dec 10, 2024
Added
Jun 30, 2025
Modified
Jul 11, 2025
Description
Command injection in the admin web console of Ivanti CSA before version5.0.3allows aremote authenticatedattackerwith admin privilegestoachieve remote code execution.
Solution
ivanti-cloud-services-application-upgrade-latest
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.