Vulnerabilities
Vulnerable Software
Ivanti:  Security Vulnerabilities
Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector.
CVSS Score
7.8
EPSS Score
0.002
Published
2024-10-18
Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker to achieve remote code execution.
CVSS Score
9.1
EPSS Score
0.71
Published
2024-10-18
Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.
CVSS Score
7.2
EPSS Score
0.156
Published
2024-10-08
Under specific circumstances, insecure permissions in Ivanti Velocity License Server before version 5.2 allows a local authenticated attacker to achieve local privilege escalation.
CVSS Score
7.8
EPSS Score
0.002
Published
2024-10-08
CVE-2024-9380
Known exploited
An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution.
CVSS Score
7.2
EPSS Score
0.597
Published
2024-10-08
CVE-2024-9379
Known exploited
SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
CVSS Score
6.5
EPSS Score
0.438
Published
2024-10-08
Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.
CVSS Score
7.3
EPSS Score
0.378
Published
2024-10-08
Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information
CVSS Score
7.5
EPSS Score
0.563
Published
2024-10-08
Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application components.
CVSS Score
8.8
EPSS Score
0.002
Published
2024-10-08
A NULL pointer dereference in WLAvalancheService.exe of Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to cause a denial of service.
CVSS Score
7.5
EPSS Score
0.017
Published
2024-10-08


Contact Us

Shodan ® - All rights reserved