An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.
Conclusion & alert: CVE-2024-8190 is rated Critical Active Threat (85.8/100): CVSS High severity, with high exploitation likelihood (EPSS 89.04%, 100th percentile).Core evidence: CISA KEV confirms active exploitation (added 2024-09-13) affecting Ivanti / Cloud Services Appliance. a weakness (CWE-78) Unauthenticated remote administrative access may be possible.Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Required action: As Ivanti CSA has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line of supported solutions, as future vulnerabilities on the 4.6.x version of CSA are unlikely to receive future security updates.
Exploit prediction scoring system (EPSS) score for CVE-2024-8190
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).