Show filters
77 Total Results
Displaying 11-20 of 77
Sort by:
Attacker Value
Unknown
CVE-2024-7571
Disclosure Date: November 12, 2024 (last updated January 18, 2025)
Incorrect permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.
0
Attacker Value
Unknown
CVE-2023-38042
Disclosure Date: May 31, 2024 (last updated June 01, 2024)
A local privilege escalation vulnerability in Ivanti Secure Access Client for Windows allows a low privileged user to execute code as SYSTEM.
0
Attacker Value
Unknown
CVE-2024-3661
Disclosure Date: May 06, 2024 (last updated January 16, 2025)
DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.
0
Attacker Value
Unknown
CVE-2024-22318
Disclosure Date: February 09, 2024 (last updated February 17, 2024)
IBM i Access Client Solutions (ACS) 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.4 is vulnerable to NT LAN Manager (NTLM) hash disclosure by an attacker modifying UNC capable paths within ACS configuration files to point to a hostile server. If NTLM is enabled, the Windows operating system will try to authenticate using the current user's session. The hostile server could capture the NTLM hash information to obtain the user's credentials. IBM X-Force ID: 279091.
0
Attacker Value
Unknown
CVE-2023-45185
Disclosure Date: December 14, 2023 (last updated December 19, 2023)
IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to execute remote code. Due to improper authority checks the attacker could perform operations on the PC under the user's authority. IBM X-Force ID: 268273.
0
Attacker Value
Unknown
CVE-2023-45182
Disclosure Date: December 14, 2023 (last updated December 19, 2023)
IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 is vulnerable to having its key for an encrypted password decoded. By somehow gaining access to the encrypted password, a local attacker could exploit this vulnerability to obtain the password to other systems. IBM X-Force ID: 268265.
0
Attacker Value
Unknown
CVE-2023-45184
Disclosure Date: December 14, 2023 (last updated December 19, 2023)
IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to obtain a decryption key due to improper authority checks. IBM X-Force ID: 268270.
0
Attacker Value
Unknown
CVE-2023-41718
Disclosure Date: November 15, 2023 (last updated November 23, 2023)
When a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the affected system when having control over a specific file.
0
Attacker Value
Unknown
CVE-2023-38544
Disclosure Date: November 15, 2023 (last updated November 23, 2023)
A logged in user can modify specific files that may lead to unauthorized changes in system-wide configuration settings. This vulnerability could be exploited to compromise the integrity and security of the network on the affected system.
0
Attacker Value
Unknown
CVE-2023-38543
Disclosure Date: November 15, 2023 (last updated November 23, 2023)
A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine.
0