CVE Vulnerabilities

CVE-2024-11639

Authentication Bypass Using an Alternate Path or Channel

Published: Dec 10, 2024 | Modified: Jan 17, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

Name Vendor Start Version End Version
Cloud_services_appliance Ivanti * 5.0.3 (excluding)

Potential Mitigations

References