Show filters
423 Total Results
Displaying 271-280 of 423
Sort by:
Attacker Value
Unknown
CVE-2023-35084
Disclosure Date: October 18, 2023 (last updated February 25, 2025)
Unsafe Deserialization of User Input could lead to Execution of Unauthorized Operations in Ivanti Endpoint Manager 2022 su3 and all previous versions, which could allow an attacker to execute commands remotely.
0
Attacker Value
Unknown
CVE-2023-35083
Disclosure Date: October 18, 2023 (last updated October 25, 2023)
Allows an authenticated attacker with network access to read arbitrary files on Endpoint Manager recently discovered on 2022 SU3 and all previous versions potentially leading to the leakage of sensitive information.
0
Attacker Value
Unknown
CVE-2023-38344
Disclosure Date: September 21, 2023 (last updated February 25, 2025)
An issue was discovered in Ivanti Endpoint Manager before 2022 SU4. A file disclosure vulnerability exists in the GetFileContents SOAP action exposed via /landesk/managementsuite/core/core.secure/OsdScript.asmx. The application does not sufficiently restrict user-supplied paths, allowing for an authenticated attacker to read arbitrary files from a remote system, including the private key used to authenticate to agents for remote access.
0
Attacker Value
Unknown
CVE-2023-38343
Disclosure Date: September 21, 2023 (last updated February 25, 2025)
An XXE (XML external entity injection) vulnerability exists in the CSEP component of Ivanti Endpoint Manager before 2022 SU4. External entity references are enabled in the XML parser configuration. Exploitation of this vulnerability can lead to file disclosure or Server Side Request Forgery.
0
Attacker Value
Unknown
CVE-2023-32565
Disclosure Date: August 10, 2023 (last updated October 08, 2023)
An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. Fixed in version 6.4.1.
0
Attacker Value
Unknown
CVE-2023-32564
Disclosure Date: August 10, 2023 (last updated February 25, 2025)
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution.
0
Attacker Value
Unknown
CVE-2023-32563
Disclosure Date: August 10, 2023 (last updated February 25, 2025)
An unauthenticated attacker could achieve the code execution through a RemoteControl server.
0
Attacker Value
Unknown
CVE-2023-32562
Disclosure Date: August 10, 2023 (last updated February 25, 2025)
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution. Fixed in version 6.4.1.
0
Attacker Value
Unknown
CVE-2023-32561
Disclosure Date: August 10, 2023 (last updated October 08, 2023)
A previously generated artifact by an administrator could be accessed by an attacker. The contents of this artifact could lead to authentication bypass. Fixed in version 6.4.1.
0
Attacker Value
Unknown
CVE-2023-32560
Disclosure Date: August 10, 2023 (last updated February 25, 2025)
An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code execution.
Thanks to a Researcher at Tenable for finding and reporting.
Fixed in version 6.4.1.
0