Vulnerability threat dossier

CVE-2024-8190

ivanticloud services appliance

An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.

VTP deterministic threat59.7of 100 · CVSS excluded

VTP analyst assessment

Ivanti CSA authenticated command injection

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence95%
Public exploitation · VTP factKEV

Assessment

High-severity OS command injection in Ivanti CSA 4.6 Patch 518 and earlier, enabling remote code execution by an authenticated administrator. Supplied KEV context and independent ENISA EU KEV evidence establish known global exploitation.

Why it matters

  • Successful exploitation yields high confidentiality, integrity, and availability impact despite requiring admin privileges.
  • EPSS 0.88535 indicates high predictive likelihood but is not exploitation proof.

Evidence

2 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 1 independent evidence group.

Uncertainties

A press-linked zero-day assertion has unknown independence and no detailed linkage in the supplied excerpt.

The required admin access, local version state, and any compromise are unknown.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

CSA 4.6 Patch 518 or earlier and unexpected use of administrative accounts.

AI baseline history (3)
  1. BASELINE ASSESSED
    Ivanti CSA authenticated command injectiongpt-5.6-sol · high
  2. BASELINE ASSESSED
    Ivanti CSA authenticated command injectiongpt-5.6-sol · high
  3. BASELINE ASSESSED
    Ivanti CSA authenticated OS command injectiongpt-5.6-sol · high
Technical severityHIGHCVSS 7.2 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS0.89100th percentile · prediction
Evidence confidence95%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    EPSS is 0.89; this is predictive context, not exploitation evidence.

  3. 03

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

KEV ADDEDCISA KEV entry added
03

Claim provenance

Evidence and source independence

2publications detected
2underlying evidence chains

1 primary sources · 0 dependent secondary reports · 1 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimZERO DAYPUBLICATION REPORTS ZERO DAY
64%claim confidence
UNKNOWNreport:a3245ac22fbdfa682646d4fa3328850e649e7d6f999276e27ad1da895c6cdfd9ACTIVE
Evidence
Source claimACTIVE EXPLOITATIONENISA EU KEV LISTED
95%claim confidence
INDEPENDENTcatalog:enisa-eu-kev:CVE-2024-8190ACTIVE
Evidence
04

Event history

Threat timeline

  1. 16:4226 Aug
    ZERO DAY

    Zero Day

    The Hacker News supplied a deterministically extracted signal; review the linked evidence before escalation.

  2. 00:0013 Sept
    ACTIVE EXPLOITATION

    ENISA EU KEV entry added

    ENISA EU KEV reports known exploitation. VTP imported this historical entry as source baseline. This is public intelligence, not a VTP sensor observation.

  3. 00:0013 Sept
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

05

Original publications

Source record

FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country. The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司).&

CVE-2018-13379CVE-2019-10068CVE-2019-19781CVE-2020-5902CVE-2021-26855CVE-2021-44228CVE-2023-22515CVE-2024-24919CVE-2024-8190CVE-2024-8963CVE-2024-9380CVE-2025-31161CVE-2026-1731
Separate evidence group
Original

ENISA EU KEV catalog membership for CVE-2024-8190

ENISA EU KEV lists this vulnerability as known to be exploited. This is public intelligence, not a VTP sensor observation.

CVE-2024-8190
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score59.7vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction17.71 / 20
Exploit availability2.5 / 15
Source independence7.5 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
7.2 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-78
CPE records
2
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.