A vulnerability has been identified in Ivanti Cloud Services Appliance (CSA) 4.6. The vulnerability could allow for OS Command Injection against the host device. The vulnerability (CVE-2024-8190) has a High CVSSv3.1 score of 7.2 out of 10.
Ivanti made customers aware of a security update released for the 4.6 version of Cloud Services Appliance which resolved an OS Command Injection vulnerability, allowing remote authenticated attackers to obtain remote code execution capabilities on the target. Although version 4.6 of the software is in End-of-Life in favor of the currently supported 5.0, several organizations have not made the transition yet.
In September 13, Ivanti confirmed exploitation of the vulnerability in the wild following reports from customers. This underlines the need to promptly upgrade to the up to date, known safe 5.0 version.
Ivanti Cloud Services Appliance (CSA) version 4.6 (before patch 519) is vulnerable to the attack.
https://nvd.nist.gov/vuln/detail/CVE-2024-8190