CVE-2024-9381: Ivanti Endpoint Manager Cloud Services Appliance
High severity, CVSS 7.2. EPSS: 15.6% chance of exploitation in the next 30 days.
Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.
Affected products
- Ivanti Endpoint Manager Cloud Services Appliance: before 5.0.2 (fixed in 5.0.2)
Published 2024-10-08. Last modified 2026-06-17.