CVE-2021-44529: Ivanti EPM Cloud Services Appliance code injection, unauthenticated RCE
The short version: CVE-2021-44529 is a code-injection flaw in the Ivanti Endpoint Manager Cloud Services Appliance (CSA) that lets an unauthenticated attacker execute arbitrary code on the device. The CSA is designed to sit on the internet as a gateway for managed endpoints, so this is directly reachable. It's in CISA's KEV catalog with known ransomware-campaign use. If you run an affected CSA, patch and verify. Steady hands — but move.
At a glance
| Fact | Detail |
|---|---|
| Our severity take | High — unauthenticated code execution on an internet-facing gateway |
| CVSS v3.1 (NVD) | 9.8 — Critical · AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | ~99.1% · 99.93rd percentile (2026-07-17) |
| In CISA KEV? | Yes — remediation was due 2024-04-15 |
| Known exploited? | Yes — KEV notes known ransomware-campaign use |
| Vulnerability type | CWE-94 code injection → arbitrary code execution (as the "nobody" user) |
| Requires authenticated session? | No — pre-authentication |
| Affected | Ivanti EPM Cloud Services Appliance (CSA) — see advisory SA-2021-12-02 for versions |
| Fixed in | Patched CSA build per Ivanti advisory SA-2021-12-02 |
What you need to know
CVE-2021-44529 lets an unauthenticated attacker inject and run code on the Cloud Services Appliance. The code runs with limited ("nobody") permissions rather than root, which caps the immediate blast radius — but a foothold on an internet-facing gateway is still a foothold, and attackers routinely chain a low-privilege execution into more.
Why it belongs at the top of the queue:
- It's pre-authentication and internet-facing. The CSA is meant to be reachable so managed endpoints can phone home, so no credentials and no chain are needed to reach the flaw.
- It's a management-plane appliance. The CSA fronts Ivanti Endpoint Manager, which pushes software to endpoints — a compromise here is a dangerous place to stand.
- It's confirmed exploited. CISA added it to KEV and flags known ransomware-campaign use.
How serious we see it
High — in practice and on paper.
Unauthenticated code execution on an internet-facing appliance, confirmed exploited and tied to ransomware, is top-of-queue even though the initial code runs unprivileged. The "nobody" ceiling is a mild comfort, not a mitigation — the practical risk is a beachhead on a management gateway. The bounded, reassuring part: it affects a specific product, a fix exists, and exposure is quick to determine. Because it was exploited in the wild, treat an exposed, unpatched CSA as potentially compromised.
Recommendations
Straight from Ivanti's advisory and CISA:
- Patch now. Apply the fixed CSA build from Ivanti advisory SA-2021-12-02.
- Hunt for compromise. Review appliance logs and look for web shells or unexpected files, given the pre-patch exploitation history.
- If compromised, respond fully. Rebuild the appliance and rotate all credentials, keys, and certificates it held.
- Harden exposure. Restrict who can reach the CSA; keep management interfaces off the public internet wherever possible.
- Confirm your exposure first. Verify whether you run an affected CSA at all.
How BreachRisk sees it
BreachRisk works from the outside in. From little more than your domain it discovers internet-facing Ivanti CSA / Endpoint Manager gateways, fingerprints the product and version, and flags exposure tied to KEV-listed, actively exploited vulnerabilities like this one — surfaced at the top of your results because it's in KEV.
That continuous, attacker's-eye view is the point: the management gateway you stood up and half-forgot is exactly what an attacker scans for, so BreachRisk keeps it mapped and prioritized.