A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
https://veriti.ai/blog/vulnerable-villain-when-hackers-get-hacked/
https://forums.ivanti.com/s/article/SA-2021-12-02?language=en_US
https://www.crowdstrike.com/blog/anatomy-of-alpha-spider-ransomware/