VDB

CVE-2021-44529

CVE-2021-44529 PUBLISHED KEV CVSS 7.5 HIGH

A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).

EPSS 94.46% · 100.0th percentile

Risk Scores

CVSS 2.0
7.5
EPSS Score
94.46%
100.0th percentile

Affected Products

VendorProductVersions
ivantiendpoint_manager_cloud_services_appliance0
n/aIvanti EPM4.6.0-512
ivantiendpoint_manager_cloud_services_appliance0, 4.6

Timeline

  • CVE Published
  • Dec 9, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Mar 20, 2022 EPSS Score
  • Mar 22, 2022 PoC Published
  • Mar 23, 2022 EPSS Score
  • Mar 28, 2022 EPSS Score
  • Jul 15, 2022 EPSS Score
  • Jul 16, 2022 EPSS Score
  • Nov 2, 2022 EPSS Score
  • Nov 15, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›