Vulnerabilities
Vulnerable Software
Ivanti:  Security Vulnerabilities
CVE-2021-44529
Known exploited
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
CVSS Score
9.8
EPSS Score
0.945
Published
2021-12-08
An improper access control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform a session takeover.
CVSS Score
8.8
EPSS Score
0.043
Published
2021-12-07
An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to write dangerous files.
CVSS Score
8.8
EPSS Score
0.65
Published
2021-12-07
An improper authorization control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform privilege escalation.
CVSS Score
8.8
EPSS Score
0.057
Published
2021-12-07
A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 using Inforail Service allows arbitrary code execution via Data Repository Service.
CVSS Score
9.8
EPSS Score
0.54
Published
2021-12-07
An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 using inforail Service allows Privilege Escalation via Enterprise Server Service.
CVSS Score
9.8
EPSS Score
0.169
Published
2021-12-07
A command injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary command execution.
CVSS Score
8.8
EPSS Score
0.696
Published
2021-12-07
A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary code execution.
CVSS Score
8.8
EPSS Score
0.767
Published
2021-12-07
A SQL Injection vulnerability exists in Ivanti Avalance before 6.3.3 allows an attacker with access to the Inforail Service to perform privilege escalation.
CVSS Score
8.8
EPSS Score
0.273
Published
2021-12-07
A command Injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary command execution.
CVSS Score
8.8
EPSS Score
0.696
Published
2021-12-07


Contact Us

Shodan ® - All rights reserved