VDB

CVE-2021-44529

CVE-2021-44529 PUBLISHED KEV CVSS 7.5 HIGH

A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).

EPSS 99.11% · 99.9th percentile

Risk Scores

CVSS 2.0
7.5
EPSS Score
99.11%
99.9th percentile

Affected Products

VendorProductVersions
ivantiendpoint_manager_cloud_services_appliance0
n/aIvanti EPM4.6.0-512
ivantiendpoint_manager_cloud_services_appliance0, 4.6

Timeline

  • CVE Published
  • Dec 9, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Mar 20, 2022 EPSS Score
  • Mar 22, 2022 PoC Published
  • Mar 23, 2022 EPSS Score
  • Mar 24, 2022 VulnCheck XDB Entry
  • Mar 28, 2022 EPSS Score
  • Apr 16, 2022 VulnCheck XDB Entry
  • Jul 15, 2022 EPSS Score
  • Jul 16, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›