CVE-2021-44529
Description
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
NVD
Severity: CRITICAL
CVE ID: CVE-2021-44529
CVSS Score: 9.8
CVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Proof Of Concept
Nuclei Templates for CVE-2021-44529
Refrence: Project Discovery GitHub
jkana
CVE-2021-44529 PoC
Refrence: GitHub
jax7sec
CVE-2021-44529 Ivanti EPM 云服务设备 (CSA) 中的代码注入漏洞允许未经身份验证的用户以有限的权限(nobody)执行任意代码。
Refrence: GitHub