Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Attackers exploited a second vulnerability in Ivanti’s Cloud Services Appliance (CSA) in September 2024, chaining critical path-traversal flaw CVE-2024-8963 with CVE-2024-8190, an OS-command-injection bug. The combination could bypass administrative authentication and enable arbitrary command execution on vulnerable appliances.
This involved an on-premises network appliance—not necessarily Ivanti’s hosted cloud services. Organizations still running CSA 4.6 should treat Patch 519 as an emergency minimum and prioritize migration to a supported release.
What happened
Ivanti disclosed active exploitation of CVE-2024-8963 on September 19, 2024. The vulnerability affected Cloud Services Appliance 4.6 installations before Patch 519. Attackers could use the path-traversal flaw to reach restricted functionality without authentication and then chain it with CVE-2024-8190.
Free tools Windows power users keep installed
One-click scans. No signup required.
CVE-2024-8190, disclosed earlier, was an OS-command-injection vulnerability that could provide remote code execution when exploited by a remote attacker with administrator-level privileges. CVE-2024-8963 materially changed that risk by helping attackers overcome the relevant access-control barrier.
#1 Best Overall
- INTEGRATED FIREWALL APPLIANCE AND SECURITY SERVICES: Comes with FortiGate-40F Firewall Appliance, 3 years of FortiCare Premium, and FortiGuard Unified Threat Protection.
- UTP SECURITY FEATURES: Offers protection from advanced threats with DNS filtering, URL filtering, video filtering, and controls against botnets.
- IDEAL FOR SMALLER SETTINGS: Best suited for small to mid-sized businesses needing reliable security without the complexity of larger systems.
- CONTINUOUS SUPPORT AND MAINTENANCE: FortiCare Premium ensures that technical help is readily available to manage and troubleshoot issues.
- COMPACT AND EFFECTIVE: Provides a powerful, yet compact security solution that effectively protects against a wide range of cyber threats.
That does not establish that every exposed CSA appliance was compromised. It does establish that vulnerable, reachable deployments faced active exploitation and required urgent remediation.
The two vulnerabilities
| CVE | Bug | Condition when considered alone | Potential result |
|---|---|---|---|
| CVE-2024-8963 | Path traversal (CWE-22) | Remote, unauthenticated access to restricted functionality | Access-control bypass and an entry point for the attack chain |
| CVE-2024-8190 | OS command injection | Authentication and administrator-level privileges | Remote code execution |
Ivanti assigned CVE-2024-8963 a CVSS 3.1 score of 9.4, rated Critical. NVD lists a 9.1 Critical score. The difference reflects scoring assessments by different authorities; both indicate a severe vulnerability. CVE-2024-8190 carries a 7.2 High score.
How the chain increased the danger
- Reach restricted functionality: CVE-2024-8963 could let a remote, unauthenticated attacker access functionality that should have been protected.
- Cross the privilege barrier: That access could be used in the context of CVE-2024-8190, which otherwise required administrator-level privileges.
- Execute commands: The command-injection flaw could then be used to execute arbitrary commands on the appliance.
It is therefore misleading to describe CVE-2024-8190 alone as an unauthenticated remote-code-execution vulnerability. The reported risk came from chaining two flaws with different roles in the attack.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Rank #2
- HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
- UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
- OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
- RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
- EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
Which CSA versions were affected?
| CSA state | Status |
|---|---|
| CSA 4.6 before Patch 519 | Affected |
| CSA 4.6 Patch 519 | Listed as fixed for the cited vulnerabilities |
| CSA 5.0 | Listed as fixed |
| CSA 4.6 generally | End of life and unsuitable as a long-term security strategy |
The durable recommendation is to migrate from CSA 4.6 to CSA 5.0 or the currently supported Ivanti migration path available under the organization’s entitlement. Applying Patch 519 may be necessary as an emergency step, but it does not restore long-term support to the end-of-life 4.6 branch. Confirm current release, lifecycle, compatibility, and entitlement details through Ivanti Support.
CISA’s exploitation warning
CISA added CVE-2024-8190 to its Known Exploited Vulnerabilities catalog on September 13, 2024, with an October 4 deadline for applicable U.S. federal civilian agencies. CVE-2024-8963 was added on September 19, with an October 10 deadline.
Those deadlines apply to federal civilian agencies under the relevant requirements. Other organizations should treat the dates as urgent remediation benchmarks rather than automatically binding deadlines. KEV listing confirms known exploitation; it does not prove that every CSA customer was breached.
Rank #3
- Comprehensive Hardware and Service Package: Purchase includes the FortiGate-90G appliance combined with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection (UTP).
- Unified Threat Protection (UTP) Bundle: Offers robust web security services that protect against web-borne threats, including sophisticated DNS-based threats.
- Advanced Filtering and Security Features: Features ATP, DNS filtering, URL filtering, video filtering, and anti-botnet and C2 communications services, securing your organization against a range of advanced threats.
- Extended Web Security: Effectively blocks malicious URLs and filters content to maintain high security standards and regulatory compliance.
- Ideal for Various Enterprise Environments: Suitable for businesses seeking to enhance their defense against increasingly complex security threats.
What administrators should do
1. Inventory every appliance
Identify production, test, dormant, disaster-recovery, and inherited CSA deployments. Record each appliance’s version, patch level, Internet exposure, management interface, network placement, and connected systems.
Recommended Free Tools
2. Restrict exposure
Limit external access to the appliance while remediation and investigation proceed. Ivanti’s contemporary guidance included using a dual-homed configuration with eth0 on the internal network. Do not apply that instruction mechanically: validate the appliance’s traffic flows, interface roles, management model, and segmentation design first.
3. Patch immediately, then migrate
If an affected CSA 4.6 appliance cannot be migrated at once, apply Patch 519 as an emergency measure where applicable. Treat migration to CSA 5.0 or a currently supported successor as the actual remediation plan.
Rank #4
- Integrated Hardware and Security Services: Comes with FortiGate-40F hardware, 5 year of FortiCare Premium, and FortiGuard Unified Threat Protection.
- UTP Security Features: Offers protection from advanced threats with DNS filtering, URL filtering, video filtering, and controls against botnets.
- Ideal for Smaller Settings: Best suited for small to mid-sized businesses needing reliable security without the complexity of larger systems.
- Continuous Support and Maintenance: FortiCare Premium ensures that technical help is readily available to manage and troubleshoot issues.
- Compact and Effective: Provides a powerful, yet compact security solution that effectively protects against a wide range of cyber threats.
4. Investigate before declaring success
Patching blocks the known vulnerability but does not prove that an attacker did not access the appliance beforehand. Review:
- New or modified administrator accounts
- Unexpected authentication activity and configuration changes
- Unusual processes, commands, scheduled activity, or outbound connections
- Firewall, VPN, identity, SIEM, and network-flow records
- Endpoint-detection-and-response alerts on connected systems
EDR may not run on a specialized appliance itself, so a lack of EDR alerts is not evidence that the CSA was uncompromised.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →5. Respond to evidence of compromise
Preserve appliance, network, identity, and endpoint evidence before resetting or rebuilding when forensic, legal, regulatory, or threat-hunting requirements apply. Coordinate with incident responders or Ivanti Support as appropriate.
Best Value
- - Only Item, License or Subsriptions sold seperately -
Where unauthorized access is plausible, rotate credentials that may have been exposed or used through the appliance, reassess privileged and service accounts, and investigate possible lateral movement. Rebuild from a trusted supported image rather than merely patching when compromise is confirmed or strongly suspected. Validate segmentation and administrative access before returning the replacement to production.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What this incident shows
A vulnerability’s practical danger depends on how it fits into an attack chain. CVE-2024-8190 had a significant privilege requirement when considered alone, but CVE-2024-8963 helped remove that barrier. The incident also illustrates why end-of-life appliances create continuing exposure: an emergency patch can address a known defect without providing a sustainable support position.
Later government reporting described broader Ivanti CSA vulnerability chaining involving additional flaws, including CVE-2024-9380. That later advisory should not be collapsed into the specific September 2024 disclosure covered here; it reflects a wider set of activity and vulnerabilities. See the CISA joint advisory for that later context.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchQuick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

