Show filters
101 Total Results
Displaying 31-40 of 101
Sort by:
Attacker Value
Unknown
CVE-2024-11004
Disclosure Date: November 12, 2024 (last updated January 18, 2025)
Reflected XSS in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required.
0
Attacker Value
Unknown
CVE-2024-9420
Disclosure Date: November 12, 2024 (last updated January 18, 2025)
A use-after-free in Ivanti Connect Secure before version 22.7R2.3 and 9.1R18.9
and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker to achieve remote code execution
0
Attacker Value
Unknown
CVE-2024-8495
Disclosure Date: November 12, 2024 (last updated January 18, 2025)
A null pointer dereference in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote unauthenticated attacker to cause a denial of service.
0
Attacker Value
Unknown
CVE-2024-47909
Disclosure Date: November 12, 2024 (last updated November 19, 2024)
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.
0
Attacker Value
Unknown
CVE-2024-47906
Disclosure Date: November 12, 2024 (last updated January 18, 2025)
Excessive binary privileges in Ivanti Connect Secure before version 22.7R2.3 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.2 (Not Applicable to 9.1Rx) allows a local authenticated attacker to escalate privileges.
0
Attacker Value
Unknown
CVE-2024-47905
Disclosure Date: November 12, 2024 (last updated November 19, 2024)
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.
0
Attacker Value
Unknown
CVE-2024-11007
Disclosure Date: November 12, 2024 (last updated November 22, 2024)
Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code execution.
0
Attacker Value
Unknown
CVE-2024-37131
Disclosure Date: June 13, 2024 (last updated February 05, 2025)
SCG Policy Manager, all versions, contains an overly permissive Cross-Origin Resource Policy (CORP) vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of malicious actions on the application in the context of the authenticated user.
0
Attacker Value
Unknown
CVE-2024-3661
Disclosure Date: May 06, 2024 (last updated January 16, 2025)
DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.
0
Attacker Value
Unknown
CVE-2024-29205
Disclosure Date: April 25, 2024 (last updated April 25, 2024)
An Improper Check for Unusual or Exceptional Conditions vulnerability in the web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a remote unauthenticated attacker to send specially crafted requests in-order-to cause service disruptions.
0