CVE-2024-9379 MEDIUM

CVE-2024-9379

Weakness CWE-89 · SQLi
KEV Status Known Exploited
Published October 8, 2024
Last update October 21, 2025

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

What the vulnerability does

01Description

SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.

CISA mandated remediation

02CISA Required Action

As Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line, or later, of supported solution.

Key dates

03Disclosure timeline

October 8, 2024 CVE published
October 21, 2025 Record updated