An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.
https://thehackernews.com/2024/10/nation-state-attackers-exploiting.html
https://thehackernews.com/2024/10/zero-day-alert-three-critical-ivanti.html
https://www.securityweek.com/third-recent-ivanti-product-vulnerability-exploited-in-the-wild/
https://thehackernews.com/2024/09/critical-ivanti-cloud-appliance.html
https://thehackernews.com/2024/09/ivanti-warns-of-active-exploitation-of.html