CVE-2021-44529: Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA)
Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability . Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code with limited permissions (nobody).
- CISA KEV-listed (remediation due 2024-04-15)
- used in ransomware campaigns
- EPSS 94.5% (100.0% percentile)