An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.
| Software | From | Fixed in |
|---|---|---|
| ivanti / cloud_services_appliance | 4.6 | 4.6.x |
| ivanti / cloud_services_appliance | 4.6-patch_518 | 4.6-patch_518.x |