VYPR

Endpoint Manager Cloud Services Appliance

by Ivanti

CVEs (5)

  • CVE-2021-44529CriKEVDec 8, 2021
    risk 0.93cvss 9.8epss 0.99

    A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).

  • CVE-2024-8963CriKEVSep 19, 2024
    risk 0.81cvss 9.4epss 0.99

    Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.

  • CVE-2024-9380HigKEVOct 8, 2024
    risk 0.64cvss 7.2epss 0.63

    An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution.

  • CVE-2024-9379MedKEVOct 8, 2024
    risk 0.58cvss 6.5epss 0.43

    SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.

  • CVE-2024-9381HigOct 8, 2024
    risk 0.48cvss 7.2epss 0.16

    Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.