S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-44529 Scanner

Targets the Self-Service Portal endpoint; unauthenticated attackers can inject arbitrary code with limited permissions, potentially leading to full system compromise.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2021-44529
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Ivanti EPMby n/a
4.6.0-512
endpoint_manager_cloud_services_applianceby ivanti
0
Updated Aug 21, 2026View on NVD →
Detail

Ivanti EPM (Endpoint and User Workspace Management) is a cloud-based solution that enables IT administrators to automate endpoint management, application deployment, patch management, and user access control from a single console. The Cloud Services Appliance (CSA) is a critical component providing cloud-based management services for IT assets. Organizations of all sizes use Ivanti EPM to streamline IT operations and enhance security posture.

CVE-2021-44529 is a code injection vulnerability in the Ivanti EPM CSA that arises due to improper input validation in the Self-Service Portal. The vulnerability allows an unauthenticated attacker to inject arbitrary code into the system. This occurs because the application fails to sanitize user-supplied input before processing it, enabling attackers to bypass authentication and execute malicious commands.

Specifically, the vulnerability is located in the Self-Service Portal endpoint of the Ivanti EPM CSA. The vulnerable parameter is the 'action' parameter, which is used to handle user requests. An attacker can craft a malicious HTTP request containing injected code in this parameter, which the server then executes with limited permissions. This affects all versions prior to 2021.3.1.

If exploited, an attacker can execute arbitrary code with limited permissions, potentially leading to full system takeover. This could result in unauthorized access to sensitive data, credential theft, lateral movement within the network, and disruption of critical business operations. The high CVSS score of 9.8 underscores the severity and ease of exploitation.

Solution Advice
  • Upgrade Ivanti EPM CSA to version 2021.3.1 or later immediately.
  • If upgrade is not possible, disable the Ivanti EPM Self-Service Portal until the CSA is updated.
  • Implement strong input validation and sanitization for all user-supplied parameters, especially the 'action' parameter.
  • Apply the principle of least privilege to limit the permissions of the CSA service account.
  • Enable web application firewall (WAF) rules to block malicious code injection attempts.
  • Monitor system logs for suspicious activity, such as unexpected HTTP requests to the Self-Service Portal.
  • Conduct regular vulnerability scans using tools like S4E to detect and remediate similar issues.
  • Enforce multi-factor authentication (MFA) for all administrative access to the Ivanti EPM console.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.