VYPR

Cloud Services Appliance

by Ivanti

CVEs (7)

  • CVE-2024-8190HigKEVSep 10, 2024
    risk 0.66cvss 7.2epss 0.89

    An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.

  • CVE-2024-11639CriDec 10, 2024
    risk 0.65cvss 10.0epss 0.05

    An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access

  • CVE-2024-47908CriFeb 11, 2025
    risk 0.61cvss 9.1epss 0.22

    OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-11773CriDec 10, 2024
    risk 0.61cvss 9.1epss 0.24

    SQL injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.

  • CVE-2024-11772CriDec 10, 2024
    risk 0.60cvss 9.1epss 0.08

    Command injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2025-22460HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.00

    Default credentials in Ivanti Cloud Services Application before version 5.0.5 allows a local authenticated attacker to escalate their privileges.

  • CVE-2024-11771MedFeb 11, 2025
    risk 0.35cvss 5.3epss 0.01

    Path traversal in Ivanti CSA before version 5.0.5 allows a remote unauthenticated attacker to access restricted functionality.