peter bassill · operator
$ cve CVE-2024-11639 JSON

CVE-2024-11639

10.0
CRITICAL · CVSS 3.1 · EPSS 4.9% (pctl 92)

In your normal cycle

Critical by CVSS (10), but no sign of active exploitation.

Description

An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS4.87% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-288
On CISA KEVno
Public exploitnone known
Published2024-12-10
Last modified2026-06-17

Affected (1)

VendorProduct
ivanticloud services appliance

References

→ the Explorer  ·  watch your stack  ·  NVD