Home

Description

An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access

PUBLISHED Reserved 2024-11-22 | Published 2024-12-10 | Updated 2024-12-14 | Assigner ivanti




CRITICAL: 10.0CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Problem types

CWE-288: Authentication Bypass Using an Alternate Path or Channel

Product status

Default status
affected

5.0.3 (custom)
unaffected

References

forums.ivanti.com/...024-11639-CVE-2024-11772-CVE-2024-11773

cve.org (CVE-2024-11639)

nvd.nist.gov (CVE-2024-11639)

Download JSON