Vulnerability threat dossier

CVE-2024-8963

ivantiendpoint manager cloud services appliance

Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.

VTP deterministic threat61.7of 100 · CVSS excluded

VTP analyst assessment

Ivanti CSA unauthenticated path traversal

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence95%
Public exploitation · VTP factKEV

Assessment

Critical unauthenticated path traversal affecting Ivanti CSA before 4.6 Patch 519. Supplied KEV context and independent ENISA EU KEV evidence establish known global exploitation. A lower-confidence press-linked assertion labels it a zero-day, but the supplied excerpt does not explain that linkage.

Why it matters

  • Network-reachable exploitation can expose restricted functionality without credentials.
  • CVSS 9.4 reflects high confidentiality and integrity impact; EPSS 0.98607 is predictive context only.

Evidence

2 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 1 independent evidence group.

Uncertainties

The zero-day assertion has unknown source independence and limited supporting detail.

Local exposure, patch state, and compromise are unknown because no first-party telemetry is configured.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

CSA versions earlier than 4.6 Patch 519 exposed to untrusted networks.

AI baseline history (3)
  1. BASELINE ASSESSED
    Ivanti CSA unauthenticated path traversalgpt-5.6-sol · high
  2. BASELINE ASSESSED
    Ivanti CSA unauthenticated path traversalgpt-5.6-sol · high
  3. BASELINE ASSESSED
    Ivanti CSA unauthenticated path traversalgpt-5.6-sol · high
Technical severityCRITICALCVSS 9.4 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS0.99100th percentile · prediction
Evidence confidence95%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    EPSS is 0.99; this is predictive context, not exploitation evidence.

  3. 03

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

KEV ADDEDCISA KEV entry added
03

Claim provenance

Evidence and source independence

2publications detected
2underlying evidence chains

1 primary sources · 0 dependent secondary reports · 1 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimZERO DAYPUBLICATION REPORTS ZERO DAY
64%claim confidence
UNKNOWNreport:a3245ac22fbdfa682646d4fa3328850e649e7d6f999276e27ad1da895c6cdfd9ACTIVE
Evidence
Source claimACTIVE EXPLOITATIONENISA EU KEV LISTED
95%claim confidence
INDEPENDENTcatalog:enisa-eu-kev:CVE-2024-8963ACTIVE
Evidence
04

Event history

Threat timeline

  1. 16:4226 Aug
    ZERO DAY

    Zero Day

    The Hacker News supplied a deterministically extracted signal; review the linked evidence before escalation.

  2. 00:0019 Sept
    ACTIVE EXPLOITATION

    ENISA EU KEV entry added

    ENISA EU KEV reports known exploitation. VTP imported this historical entry as source baseline. This is public intelligence, not a VTP sensor observation.

  3. 00:0019 Sept
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

05

Original publications

Source record

FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country. The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司).&

CVE-2018-13379CVE-2019-10068CVE-2019-19781CVE-2020-5902CVE-2021-26855CVE-2021-44228CVE-2023-22515CVE-2024-24919CVE-2024-8190CVE-2024-8963CVE-2024-9380CVE-2025-31161CVE-2026-1731
Separate evidence group
Original

ENISA EU KEV catalog membership for CVE-2024-8963

ENISA EU KEV lists this vulnerability as known to be exploited. This is public intelligence, not a VTP sensor observation.

CVE-2024-8963
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score61.7vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction19.72 / 20
Exploit availability2.5 / 15
Source independence7.5 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9.4 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
CWE
CWE-22
CPE records
3
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.