CVE-2024-8963

ENISA EUVD: EUVD-2024-49510 ↗
Exploited in the Wild ✓ Confirmed 0-Day
Triaged: March 5, 2026 9 articles Published: 2024-09-19

EPSS Score

Source: FIRST.org · 2026-05-23
94.16%
probability
This CVE has a 94.16% probability of being exploited in the next 30 days.
0% Top 99.9th percentile of all CVEs 100%

CVSS v3.1

Source: VulnerabilityLookup (CIRCL)
9.4
CRITICAL
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
Low
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

Description

VulnerabilityLookup (CNA)
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.

Affected Products

Ivanti
CSA (Cloud Services Appliance)
4.6 Patch 519 5.0

Attack Intelligence

Exploits & PoC

patfire94/CVE-2024-8963

Ivanti Cloud Services Appliance - Path Traversal

0 2024-11-13
1 repo — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
85%
EPSS 94.16%
CVSS v3.1 9.4
Mentions 9
Last Seen Oct 22, 2024

CNA Information

CNA Assigner
ivanti

Analyst Note

CVE-2024-8963 is explicitly named as one of three CSA zero-days exploited in attacks according to BleepingComputer. The CVE was published 2024-09-19 and exploitation was reported shortly thereafter (CERT-FR alert 2024-10-22), indicating exploitation occurred before or immediately after patch availability, meeting zero-day criteria.

Threat Actors 18

APT 41
apt_group Information theft and espionage 🇨🇳 CN
APT 29
apt_group Information theft and espionage 🇷🇺 RU
APT 28
apt_group Information theft and espionage 🇷🇺 RU
Harvester
apt_group Information theft and espionage Unknown
Hacking Team
apt_group 🇮🇹 IT
Mirage
apt_group Information theft and espionage 🇨🇳 CN
Infy
apt_group Information theft and espionage 🇮🇷 IR
Group 27
apt_group Information theft and espionage 🇨🇳 CN
UNC5174
apt_group 🇨🇳 CN
Chimera
apt_group Information theft and espionage 🇨🇳 CN
APT 6
apt_group Information theft and espionage 🇨🇳 CN
Red October
apt_group 🇷🇺 RU
Shadow Network
apt_group Information theft and espionage 🇨🇳 CN
Mana Team
apt_group 🇨🇳 CN
APT 5
apt_group Information theft and espionage 🇨🇳 CN
PurpleHaze
apt_group Information theft and espionage 🇨🇳 CN
Beijing Group
apt_group Information theft and espionage 🇨🇳 CN
PlushDaemon
apt_group Information theft and espionage 🇨🇳 CN

Triage Info

Decided atMar 05, 2026
Published DateSep 19, 2024