vulnerability
Ivanti Cloud Services Application: CVE-2024-47908: Improper Neutralization of Special Elements used in an OS Command
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 8 | (AV:N/AC:L/Au:M/C:C/I:C/A:C) | Feb 11, 2025 | Jun 30, 2025 | Jul 11, 2025 |
Severity
8
CVSS
(AV:N/AC:L/Au:M/C:C/I:C/A:C)
Published
Feb 11, 2025
Added
Jun 30, 2025
Modified
Jul 11, 2025
Description
OS command injection in the admin web console of Ivanti CSA before version5.0.5allows aremoteauthenticated attackerwith admin privilegestoachieve remote code execution.
Solution
ivanti-cloud-services-application-upgrade-latest
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.