CVE-2021-44529
CRITICAL KEV RANSOMWARE NUCLEIIvanti Endpoint Manager Cloud Services Appliance - Code Injection
Title source: ruleDescription
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
Exploits (4)
metasploit
WORKING POC
EXCELLENT
by Jakub Kramarz · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/ivanti_csa_unauth_rce_cve_2021_44529.rb
Nuclei Templates (1)
Ivanti EPM Cloud Services Appliance Code Injection
CRITICALby duty_1g,phyr3wall,Tirtha
Shodan:
title:"LANDesk(R) Cloud Services Appliance" || http.title:"landesk(r) cloud services appliance"
FOFA:
title="landesk(r) cloud services appliance"
References (4)
Scores
CVSS v3
9.8
EPSS
0.9446
EPSS Percentile
100.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2024-03-25
VulnCheck KEV
2024-02-29
InTheWild.io
2024-03-25
ENISA EUVD
EUVD-2021-31360
Ransomware Use
Confirmed
CWE
CWE-94
Status
published
Products (2)
ivanti/endpoint_manager_cloud_services_appliance
4.6
ivanti/endpoint_manager_cloud_services_appliance
< 4.5
Published
Dec 08, 2021
KEV Added
Mar 25, 2024
Tracked Since
Feb 18, 2026