#VU98153 Path traversal in Ivanti Cloud Services Appliance (CSA) - CVE-2024-9381
Published: October 8, 2024
Ivanti Cloud Services Appliance (CSA)
Ivanti
Description
The vulnerability allows a remote user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote user can send a specially crafted HTTP request and compromise the affected system.
Note, the vulnerability is being actively exploited in the wild against Ivanti CSA 4.6 users, according to vendor's advisory. Vulnerability exploitation was chained with previously address vulnerability #VU97617 (CVE-2024-8963).