CVE-2024-8963
Expert Analysis
Professional remediation guidance
Get tailored security recommendations from our analyst team for CVE-2024-8963. We'll provide specific mitigation strategies based on your environment and risk profile.
CVSS Score
V3.1EPSS Score
v2025.03.14There is a 94.3% chance that this vulnerability will be exploited in the wild within the next 30 days.
Attack Vector Metrics
Impact Metrics
Description
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.
Available Exploits
Ivanti Cloud Services Appliance - Path Traversal
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.
Related News
CISA, in partnership with the Federal Bureau of Investigation (FBI), released Threat Actors Chained Vulnerabilities in Ivanti Cloud Service Applications. This advisory was crafted in response to active exploitation of vulnerabilities—CVE-2024-8963, an adminis…
Affected Products
Affected Versions:
Affected Versions:
Known Exploited Vulnerability
This vulnerability is actively being exploited in the wild
Remediation Status
Due Date
Added to KEV
Required Action
As Ivanti CSA has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line of supported solutions, as future vulnerabilities on the 4.6.x version of CSA are unlikely to receive security updates.
Affected Product
Ransomware Risk
GitHub Security Advisories
Community-driven vulnerability intelligence from GitHub
Advisory Details
CVSS Scoring
CVSS Score
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
References
Advisory provided by GitHub Security Advisory Database. Published: September 19, 2024, Modified: September 19, 2024
Social Media Intelligence
Real-time discussions and threat intelligence from social platforms
French Government Hit by Ivanti Hacks: A Warning for All **France's cybersecurity agency confirms that various government sectors faced significant breaches due to vulnerabilities in Ivanti software.** **Key Points:** - Hacking campaign exploited multiple zero-day vulnerabilities in Ivanti software. - Entities across government, utility, and private sectors in France were …