CVE-2021-44529 Scanner

Targets the Self-Service Portal endpoint; unauthenticated attackers can inject arbitrary code with limited permissions, potentially leading to full system compromise.

Short Info


Level

Critical

Single Scan

Single Scan

Can be used by

Asset Owner

Estimated Time

10 seconds

Time Interval

13 days 3 hours

Scan only one

Domain, IPv4, Subdomain

Toolbox

Ivanti EPM (Endpoint and User Workspace Management) is a cloud-based solution that enables IT administrators to automate endpoint management, application deployment, patch management, and user access control from a single console. The Cloud Services Appliance (CSA) is a critical component providing cloud-based management services for IT assets. Organizations of all sizes use Ivanti EPM to streamline IT operations and enhance security posture.

CVE-2021-44529 is a code injection vulnerability in the Ivanti EPM CSA that arises due to improper input validation in the Self-Service Portal. The vulnerability allows an unauthenticated attacker to inject arbitrary code into the system. This occurs because the application fails to sanitize user-supplied input before processing it, enabling attackers to bypass authentication and execute malicious commands.

Specifically, the vulnerability is located in the Self-Service Portal endpoint of the Ivanti EPM CSA. The vulnerable parameter is the 'action' parameter, which is used to handle user requests. An attacker can craft a malicious HTTP request containing injected code in this parameter, which the server then executes with limited permissions. This affects all versions prior to 2021.3.1.

If exploited, an attacker can execute arbitrary code with limited permissions, potentially leading to full system takeover. This could result in unauthorized access to sensitive data, credential theft, lateral movement within the network, and disruption of critical business operations. The high CVSS score of 9.8 underscores the severity and ease of exploitation.

Get started to protecting your digital assets