Vulnerabilities
Vulnerable Software
Ivanti:  >> Landesk Management Suite  Security Vulnerabilities
Open directories in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to remote information disclosure and arbitrary code execution.
CVSS Score
6.3
EPSS Score
0.011
Published
2019-06-03
Use of a hard-coded encryption key in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to full managed endpoint compromise by an authenticated user with read privileges.
CVSS Score
4.5
EPSS Score
0.006
Published
2019-06-03
A vulnerable upl/async_upload.asp web API endpoint in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 allows arbitrary file upload, which may lead to arbitrary remote code execution.
CVSS Score
9.8
EPSS Score
0.055
Published
2019-06-03
Improper access control and open directories in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to remote disclosure of administrator passwords.
CVSS Score
9.0
EPSS Score
0.01
Published
2019-06-03
A SQL Injection vulnerability exists in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 due to improper username sanitization in the Basic Authentication implementation in core/provisioning.secure/ProvisioningSecure.asmx in Provisioning.Secure.dll.
CVSS Score
8.1
EPSS Score
0.026
Published
2019-06-03
Buffer overflow in the collector.exe listener of the Landesk Management Suite 10.0.0.271 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large packet.
CVSS Score
9.8
EPSS Score
0.057
Published
2017-01-23


Contact Us

Shodan ® - All rights reserved