Vulnerabilities
Vulnerable Software
Ivanti:  Security Vulnerabilities
Ivanti Avalanche decodeToMap XML External Entity Processing. Fixed in version 6.4.1.236
CVSS Score
6.5
EPSS Score
0.004
Published
2023-08-10
CVE-2023-35081
Known exploited
A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) allows an authenticated administrator to write arbitrary files onto the appliance.
CVSS Score
7.2
EPSS Score
0.932
Published
2023-08-03
CVE-2023-35078
Known exploited
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.
CVSS Score
10.0
EPSS Score
0.945
Published
2023-07-25
An out-of-bounds write vulnerability on windows operating systems causes the Ivanti AntiVirus Product to crash. Update to Ivanti AV Product version 7.9.1.285 or above.
CVSS Score
8.1
EPSS Score
0.01
Published
2023-07-21
A deserialization of untrusted data exists in EPM 2022 Su3 and all prior versions that allows an unauthenticated user to elevate rights. This exploit could potentially be used in conjunction with other OS (Operating System) vulnerabilities to escalate privileges on the machine or be used as a stepping stone to get to other network attached machines.
CVSS Score
9.8
EPSS Score
0.026
Published
2023-07-01
A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege escalation or remote code execution.
CVSS Score
9.8
EPSS Score
0.786
Published
2023-07-01
An improper authentication vulnerability exists in Avalanche Premise versions 6.3.x and below that could allow an attacker to gain access to the server by registering to receive messages from the server and perform an authentication bypass.
CVSS Score
5.9
EPSS Score
0.007
Published
2023-05-09
An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain access by exploiting the SetUser method or can exploit the Race Condition in the authentication message.
CVSS Score
5.9
EPSS Score
0.018
Published
2023-05-09
A path traversal vulnerability exists in Avalanche version 6.3.x and below that when exploited could result in possible information disclosure.
CVSS Score
7.5
EPSS Score
0.399
Published
2023-05-09
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution.
CVSS Score
7.2
EPSS Score
0.866
Published
2023-05-09


Contact Us

Shodan ® - All rights reserved