Show filters
242 Total Results
Displaying 31-40 of 242
Sort by:
Attacker Value
Unknown

CVE-2024-37401

Disclosure Date: December 12, 2024 (last updated December 21, 2024)
An out-of-bounds read in IPsec of Ivanti Connect Secure before version 22.7R2.1 allows a remote unauthenticated attacker to cause a denial of service.
0
Attacker Value
Unknown

CVE-2024-37377

Disclosure Date: December 12, 2024 (last updated December 21, 2024)
A heap-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to cause a denial of service.
0
Attacker Value
Unknown

CVE-2024-9844

Disclosure Date: December 10, 2024 (last updated January 18, 2025)
Insufficient server-side controls in Secure Application Manager of Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker to bypass restrictions.
Attacker Value
Unknown

CVE-2024-11634

Disclosure Date: December 10, 2024 (last updated January 18, 2025)
Command injection in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to achieve remote code execution. (Not applicable to 9.1Rx)
Attacker Value
Unknown

CVE-2024-11633

Disclosure Date: December 10, 2024 (last updated January 18, 2025)
Argument injection in Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution
Attacker Value
Unknown

CVE-2024-39712

Disclosure Date: November 13, 2024 (last updated December 01, 2024)
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
0
Attacker Value
Unknown

CVE-2024-39711

Disclosure Date: November 13, 2024 (last updated December 01, 2024)
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
0
Attacker Value
Unknown

CVE-2024-39710

Disclosure Date: November 13, 2024 (last updated December 01, 2024)
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
0
Attacker Value
Unknown

CVE-2024-39709

Disclosure Date: November 13, 2024 (last updated November 23, 2024)
Incorrect file permissions in Ivanti Connect Secure before version 22.6R2 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1 (Not Applicable to 9.1Rx) allow a local authenticated attacker to escalate their privileges.
0
Attacker Value
Unknown

CVE-2024-38656

Disclosure Date: November 13, 2024 (last updated December 01, 2024)
Argument injection in Ivanti Connect Secure before version 22.7R2.2 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
0