PatchSiren cyber security CVE debrief
CVE-2024-9379 Ivanti CVE debrief
CVE-2024-9379 affects Ivanti Cloud Services Appliance (CSA) and is listed by CISA as a known exploited vulnerability. CISA added it to the KEV catalog on 2024-10-09 and set a remediation due date of 2024-10-30. For CSA 4.6.x, CISA's required action is to remove it from service or upgrade to the 5.0.x line or later.
- Vendor
- Ivanti
- Product
- Cloud Services Appliance (CSA)
- CVSS
- MEDIUM 6.5
- CISA KEV
- Listed
- Original CVE published
- 2024-10-09
- Original CVE updated
- 2024-10-09
- Advisory published
- 2024-10-09
- Advisory updated
- 2024-10-09
Who should care
Security teams responsible for Ivanti CSA deployments, vulnerability management, and incident response should prioritize this issue, especially where CSA 4.6.x is still in service.
Technical summary
The CVE is identified as a SQL injection vulnerability in Ivanti Cloud Services Appliance (CSA). The supplied corpus does not include exploit mechanics, affected request paths, or detailed impact analysis. The most actionable fact is that CISA has placed it in the KEV catalog, which indicates known exploitation and warrants urgent remediation.
Defensive priority
High. KEV inclusion means this issue should be treated as urgent, with remediation prioritized ahead of routine vulnerability backlogs.
Recommended defensive actions
- Inventory all Ivanti CSA instances and determine the installed version.
- If running CSA 4.6.x, remove it from service or upgrade to the 5.0.x line or later, per CISA guidance.
- Prioritize remediation before the KEV due date of 2024-10-30 where possible.
- Validate whether any instance has compensating controls or requires emergency change handling.
- Monitor for signs of unauthorized access or anomalous activity around the appliance and associated database interactions.
Evidence notes
CISA's KEV source item identifies CVE-2024-9379 as an "Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability." The provided metadata lists dateAdded as 2024-10-09 and dueDate as 2024-10-30, with knownRansomwareCampaignUse marked Unknown. The KEV metadata also states: "As Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line, or later, of supported solution." No CVSS score was supplied in the corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-9379 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-9379
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-9379 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-9379
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.