Vulnerability Details CVE-2024-10256
Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 23.1%
CVSS Severity
CVSS v3 Score 7.1
Products affected by CVE-2024-10256
-
cpe:2.3:a:ivanti:endpoint_manager:2022
-
cpe:2.3:a:ivanti:endpoint_manager:2024
-
cpe:2.3:a:ivanti:neurons_agent_platform:*
-
cpe:2.3:a:ivanti:neurons_for_patch_management:*
-
cpe:2.3:a:ivanti:patch_for_configuration_manager:*
-
cpe:2.3:a:ivanti:patch_software_development_kit:*
-
cpe:2.3:a:ivanti:security_controls:-
-
cpe:2.3:a:ivanti:security_controls:2023.1
-
cpe:2.3:a:ivanti:security_controls:2023.1.1
-
cpe:2.3:a:ivanti:security_controls:2023.2
-
cpe:2.3:a:ivanti:security_controls:2023.3
-
cpe:2.3:a:ivanti:security_controls:2023.4
-
cpe:2.3:a:ivanti:security_controls:2023.4.1
-
cpe:2.3:a:ivanti:security_controls:2024.1
-
cpe:2.3:a:ivanti:security_controls:2024.2
-
cpe:2.3:a:ivanti:security_controls:2024.2.1
-
cpe:2.3:a:ivanti:security_controls:2024.2.2
-
cpe:2.3:a:ivanti:security_controls:2024.3
-
cpe:2.3:a:ivanti:security_controls:2024.3.1
-
cpe:2.3:a:ivanti:security_controls:2024.3.2