vulnti.work

Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability

Critical CVSS 9.8 Listed in CISA KEV
CVECVE-2021-44529
First seen2024-03-25 00:00 UTC
Disclosed2021-12-08 22:15 UTC
Last updated2026-09-02 09:01 UTC
Channel statuspending_review

Summary

Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code with limited permissions (nobody).

In-depth triage · Auto channel

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Affected products

  • Ivanti:Endpoint Manager Cloud Service Appliance (EPM CSA)
  • :

Sources

  • CISA KEV DATABASE
  • NVD DATABASE

Original Links

Timeline

  1. kev_added CISA KEV
  2. kev_ingest CISA KEV
  3. nvd_ingest NVD