Show filters
423 Total Results
Displaying 161-170 of 423
Sort by:
Attacker Value
Unknown
CVE-2024-8191
Disclosure Date: September 10, 2024 (last updated September 13, 2024)
SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.
0
Attacker Value
Unknown
CVE-2024-8190
Disclosure Date: September 10, 2024 (last updated September 17, 2024)
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.
0
Attacker Value
Unknown
CVE-2024-8012
Disclosure Date: September 10, 2024 (last updated September 19, 2024)
An authentication bypass weakness in the message broker service of Ivanti Workspace Control version 10.18.0.0 and below allows a local authenticated attacker to escalate their privileges.
0
Attacker Value
Unknown
CVE-2024-44107
Disclosure Date: September 10, 2024 (last updated September 19, 2024)
DLL hijacking in the management console of Ivanti Workspace Control version 10.18.0.0 and below allows a local authenticated attacker to escalate their privileges and achieve arbitrary code execution.
0
Attacker Value
Unknown
CVE-2024-44106
Disclosure Date: September 10, 2024 (last updated September 19, 2024)
Insufficient server-side controls in the management console of Ivanti Workspace Control version 10.18.0.0 and below allows a local authenticated attacker to escalate their privileges.
0
Attacker Value
Unknown
CVE-2024-44105
Disclosure Date: September 10, 2024 (last updated September 19, 2024)
Cleartext transmission of sensitive information in the management console of Ivanti Workspace Control version 10.18.0.0 and below allows a local authenticated attacker to obtain OS credentials.
0
Attacker Value
Unknown
CVE-2024-44104
Disclosure Date: September 10, 2024 (last updated September 19, 2024)
An incorrectly implemented authentication scheme that is subjected to a spoofing attack in the management console of Ivanti Workspace Control version 10.18.0.0 and below allows a local authenticated attacker to escalate their privileges.
0
Attacker Value
Unknown
CVE-2024-44103
Disclosure Date: September 10, 2024 (last updated September 19, 2024)
DLL hijacking in the management console of Ivanti Workspace Control version 10.18.0.0 and below allows a local authenticated attacker to escalate their privileges.
0
Attacker Value
Unknown
CVE-2024-38653
Disclosure Date: August 14, 2024 (last updated August 16, 2024)
XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.
0
Attacker Value
Unknown
CVE-2024-38652
Disclosure Date: August 14, 2024 (last updated August 16, 2024)
Path traversal in the skin management component of Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to achieve denial of service via arbitrary file deletion.
0