Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Attackers exploited a second vulnerability in Ivanti’s Cloud Services Appliance (CSA) in September 2024, chaining critical path-traversal flaw CVE-2024-8963 with CVE-2024-8190, an OS-command-injection bug. The combination could bypass administrative authentication and enable arbitrary command execution on vulnerable appliances.

This involved an on-premises network appliance—not necessarily Ivanti’s hosted cloud services. Organizations still running CSA 4.6 should treat Patch 519 as an emergency minimum and prioritize migration to a supported release.

What happened

Ivanti disclosed active exploitation of CVE-2024-8963 on September 19, 2024. The vulnerability affected Cloud Services Appliance 4.6 installations before Patch 519. Attackers could use the path-traversal flaw to reach restricted functionality without authentication and then chain it with CVE-2024-8190.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CVE-2024-8190, disclosed earlier, was an OS-command-injection vulnerability that could provide remote code execution when exploited by a remote attacker with administrator-level privileges. CVE-2024-8963 materially changed that risk by helping attackers overcome the relevant access-control barrier.

#1 Best Overall
Sale
FortiGate-40F Network Security Appliance Plus 3 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-40F-BDL-950-36)
  • INTEGRATED FIREWALL APPLIANCE AND SECURITY SERVICES: Comes with FortiGate-40F Firewall Appliance, 3 years of FortiCare Premium, and FortiGuard Unified Threat Protection.
  • UTP SECURITY FEATURES: Offers protection from advanced threats with DNS filtering, URL filtering, video filtering, and controls against botnets.
  • IDEAL FOR SMALLER SETTINGS: Best suited for small to mid-sized businesses needing reliable security without the complexity of larger systems.
  • CONTINUOUS SUPPORT AND MAINTENANCE: FortiCare Premium ensures that technical help is readily available to manage and troubleshoot issues.
  • COMPACT AND EFFECTIVE: Provides a powerful, yet compact security solution that effectively protects against a wide range of cyber threats.

That does not establish that every exposed CSA appliance was compromised. It does establish that vulnerable, reachable deployments faced active exploitation and required urgent remediation.

The two vulnerabilities

CVE Bug Condition when considered alone Potential result
CVE-2024-8963 Path traversal (CWE-22) Remote, unauthenticated access to restricted functionality Access-control bypass and an entry point for the attack chain
CVE-2024-8190 OS command injection Authentication and administrator-level privileges Remote code execution

Ivanti assigned CVE-2024-8963 a CVSS 3.1 score of 9.4, rated Critical. NVD lists a 9.1 Critical score. The difference reflects scoring assessments by different authorities; both indicate a severe vulnerability. CVE-2024-8190 carries a 7.2 High score.

How the chain increased the danger

  1. Reach restricted functionality: CVE-2024-8963 could let a remote, unauthenticated attacker access functionality that should have been protected.
  2. Cross the privilege barrier: That access could be used in the context of CVE-2024-8190, which otherwise required administrator-level privileges.
  3. Execute commands: The command-injection flaw could then be used to execute arbitrary commands on the appliance.

It is therefore misleading to describe CVE-2024-8190 alone as an unauthenticated remote-code-execution vulnerability. The reported risk came from chaining two flaws with different roles in the attack.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

Which CSA versions were affected?

CSA state Status
CSA 4.6 before Patch 519 Affected
CSA 4.6 Patch 519 Listed as fixed for the cited vulnerabilities
CSA 5.0 Listed as fixed
CSA 4.6 generally End of life and unsuitable as a long-term security strategy

The durable recommendation is to migrate from CSA 4.6 to CSA 5.0 or the currently supported Ivanti migration path available under the organization’s entitlement. Applying Patch 519 may be necessary as an emergency step, but it does not restore long-term support to the end-of-life 4.6 branch. Confirm current release, lifecycle, compatibility, and entitlement details through Ivanti Support.

CISA’s exploitation warning

CISA added CVE-2024-8190 to its Known Exploited Vulnerabilities catalog on September 13, 2024, with an October 4 deadline for applicable U.S. federal civilian agencies. CVE-2024-8963 was added on September 19, with an October 10 deadline.

Those deadlines apply to federal civilian agencies under the relevant requirements. Other organizations should treat the dates as urgent remediation benchmarks rather than automatically binding deadlines. KEV listing confirms known exploitation; it does not prove that every CSA customer was breached.

Rank #3
FortiGate-90G Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-90G-BDL-950-12)
  • Comprehensive Hardware and Service Package: Purchase includes the FortiGate-90G appliance combined with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection (UTP).
  • Unified Threat Protection (UTP) Bundle: Offers robust web security services that protect against web-borne threats, including sophisticated DNS-based threats.
  • Advanced Filtering and Security Features: Features ATP, DNS filtering, URL filtering, video filtering, and anti-botnet and C2 communications services, securing your organization against a range of advanced threats.
  • Extended Web Security: Effectively blocks malicious URLs and filters content to maintain high security standards and regulatory compliance.
  • Ideal for Various Enterprise Environments: Suitable for businesses seeking to enhance their defense against increasingly complex security threats.

What administrators should do

1. Inventory every appliance

Identify production, test, dormant, disaster-recovery, and inherited CSA deployments. Record each appliance’s version, patch level, Internet exposure, management interface, network placement, and connected systems.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Restrict exposure

Limit external access to the appliance while remediation and investigation proceed. Ivanti’s contemporary guidance included using a dual-homed configuration with eth0 on the internal network. Do not apply that instruction mechanically: validate the appliance’s traffic flows, interface roles, management model, and segmentation design first.

3. Patch immediately, then migrate

If an affected CSA 4.6 appliance cannot be migrated at once, apply Patch 519 as an emergency measure where applicable. Treat migration to CSA 5.0 or a currently supported successor as the actual remediation plan.

Rank #4
FortiGate-40F Network Security Appliance Plus 5 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-40F-BDL-950-60)
  • Integrated Hardware and Security Services: Comes with FortiGate-40F hardware, 5 year of FortiCare Premium, and FortiGuard Unified Threat Protection.
  • UTP Security Features: Offers protection from advanced threats with DNS filtering, URL filtering, video filtering, and controls against botnets.
  • Ideal for Smaller Settings: Best suited for small to mid-sized businesses needing reliable security without the complexity of larger systems.
  • Continuous Support and Maintenance: FortiCare Premium ensures that technical help is readily available to manage and troubleshoot issues.
  • Compact and Effective: Provides a powerful, yet compact security solution that effectively protects against a wide range of cyber threats.

4. Investigate before declaring success

Patching blocks the known vulnerability but does not prove that an attacker did not access the appliance beforehand. Review:

  • New or modified administrator accounts
  • Unexpected authentication activity and configuration changes
  • Unusual processes, commands, scheduled activity, or outbound connections
  • Firewall, VPN, identity, SIEM, and network-flow records
  • Endpoint-detection-and-response alerts on connected systems

EDR may not run on a specialized appliance itself, so a lack of EDR alerts is not evidence that the CSA was uncompromised.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

5. Respond to evidence of compromise

Preserve appliance, network, identity, and endpoint evidence before resetting or rebuilding when forensic, legal, regulatory, or threat-hunting requirements apply. Coordinate with incident responders or Ivanti Support as appropriate.

Where unauthorized access is plausible, rotate credentials that may have been exposed or used through the appliance, reassess privileged and service accounts, and investigate possible lateral movement. Rebuild from a trusted supported image rather than merely patching when compromise is confirmed or strongly suspected. Validate segmentation and administrative access before returning the replacement to production.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What this incident shows

A vulnerability’s practical danger depends on how it fits into an attack chain. CVE-2024-8190 had a significant privilege requirement when considered alone, but CVE-2024-8963 helped remove that barrier. The incident also illustrates why end-of-life appliances create continuing exposure: an emergency patch can address a known defect without providing a sustainable support position.

Later government reporting described broader Ivanti CSA vulnerability chaining involving additional flaws, including CVE-2024-9380. That later advisory should not be collapsed into the specific September 2024 disclosure covered here; it reflects a wider set of activity and vulnerabilities. See the CISA joint advisory for that later context.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.