Vulnerabilities
Vulnerable Software
Ivanti:  Security Vulnerabilities
SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.
CVSS Score
7.8
EPSS Score
0.09
Published
2024-09-10
DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges.
CVSS Score
8.8
EPSS Score
0.002
Published
2024-09-10
An incorrectly implemented authentication scheme that is subjected to a spoofing attack in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges.
CVSS Score
8.8
EPSS Score
0.001
Published
2024-09-10
Cleartext transmission of sensitive information in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to obtain OS credentials.
CVSS Score
8.2
EPSS Score
0.0
Published
2024-09-10
Path traversal in the skin management component of Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to achieve denial of service via arbitrary file deletion.
CVSS Score
8.2
EPSS Score
0.029
Published
2024-08-14
XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.
CVSS Score
8.2
EPSS Score
0.863
Published
2024-08-14
An off-by-one error in WLInfoRailService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS.
CVSS Score
7.5
EPSS Score
0.014
Published
2024-08-14
Improper input validation in the Central Filestore in Ivanti Avalanche 6.3.1 allows a remote authenticated attacker with admin rights to achieve RCE.
CVSS Score
7.2
EPSS Score
0.028
Published
2024-08-14
A NULL pointer dereference in WLAvalancheService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS.
CVSS Score
7.5
EPSS Score
0.022
Published
2024-08-14
An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the OIDC client secret via debug information.
CVSS Score
9.6
EPSS Score
0.061
Published
2024-08-13


Contact Us

Shodan ® - All rights reserved