QID 14015
Date Published: 2023-08-14
QID 14015: Ivanti EPM Cloud Services Appliance (CSA) Code Injection Vulnerability (SA-2021-12-02)
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) before 4.6.0-512 allows an unauthenticated user to execute arbitrary code with limited permissions.
Affected Versions :
Ivanti EPM Cloud Services Appliance (CSA) before 4.6.0-512
QID Detection Logic (un-Authenticated):
This QID uses specially crafted cookie value in order to check vulnerability.
On successful exploitation it allows an unauthenticated user to execute arbitrary code with limited permissions.
Solution
Newer versions of the ISO has been released that includes the fix for this. Refer to Ivanti security advisory SA-2021-12-02 for updates and patch information.
Vendor References
- SA-2021-12-02 -
forums.ivanti.com/s/article/SA-2021-12-02?language=en_US
CVEs related to QID 14015
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SA-2021-12-02 |
|