THREATOPS
THREAT OPSThreat News › [NVD] CVE-2021-44529 (CRITICAL 9.8) — A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).

[NVD] CVE-2021-44529 (CRITICAL 9.8) — A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).

lownvdPublished 2021-12-08

CVE-2021-44529 CVSS: 9.8 CRITICAL Published: 2021-12-08T22:15:10.163

A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2021-44529