CVE Vulnerabilities

CVE-2024-11639

Authentication Bypass Using an Alternate Path or Channel

Published: Dec 10, 2024 | Modified: Jan 17, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

NameVendorStart VersionEnd Version
Cloud_services_applianceIvanti*5.0.3 (excluding)

Potential Mitigations

References