CVE-2024-9381: Ivanti Endpoint Manager Cloud Services Appliance

High severity, CVSS 7.2. EPSS: 15.6% chance of exploitation in the next 30 days.

Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.

Affected products

  • Ivanti Endpoint Manager Cloud Services Appliance: before 5.0.2 (fixed in 5.0.2)

Published 2024-10-08. Last modified 2026-06-17.