Show filters
152 Total Results
Displaying 31-40 of 152
Sort by:
Attacker Value
Unknown

CVE-2024-37344

Disclosure Date: June 20, 2024 (last updated August 07, 2024)
There is a cross-site scripting vulnerability in the Policy management UI of Absolute Secure Access prior to version 13.06. Attackers with system administrator permissions can interfere with another system administrator’s use of the policy management UI when the administrators are editing the same policy object. The scope is unchanged, there is no loss of confidentiality. Impact to system availability is none, impact to system integrity is high.
Attacker Value
Unknown

CVE-2024-37343

Disclosure Date: June 20, 2024 (last updated August 07, 2024)
There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.06. Attackers with valid tunnel credentials can pass a limited-length script to the administrative console which is then temporarily stored where an administrator using a non-default configuration could click on it while the attacker has a valid tunnel session with the server. The scope is unchanged, there is no loss of confidentiality. Impact to system availability is none, impact to system integrity is high.
Attacker Value
Unknown

CVE-2023-46810

Disclosure Date: May 31, 2024 (last updated June 01, 2024)
A local privilege escalation vulnerability in Ivanti Secure Access Client for Linux before 22.7R1, allows a low privileged user to execute code as root.
0
Attacker Value
Unknown

CVE-2023-38042

Disclosure Date: May 31, 2024 (last updated June 01, 2024)
A local privilege escalation vulnerability in Ivanti Secure Access Client for Windows allows a low privileged user to execute code as SYSTEM.
0
Attacker Value
Unknown

CVE-2024-3661

Disclosure Date: May 06, 2024 (last updated January 16, 2025)
DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.
Attacker Value
Unknown

CVE-2023-28807

Disclosure Date: January 31, 2024 (last updated February 10, 2024)
In Zscaler Internet Access (ZIA) a mismatch between Connect Host and Client Hello's Server Name Indication (SNI) enables attackers to evade network security controls by hiding their communications within legitimate traffic.
Attacker Value
Unknown

CVE-2023-6105

Disclosure Date: November 15, 2023 (last updated February 14, 2025)
An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database.
Attacker Value
Unknown

CVE-2023-41718

Disclosure Date: November 15, 2023 (last updated November 23, 2023)
When a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the affected system when having control over a specific file.
Attacker Value
Unknown

CVE-2023-38544

Disclosure Date: November 15, 2023 (last updated November 23, 2023)
A logged in user can modify specific files that may lead to unauthorized changes in system-wide configuration settings. This vulnerability could be exploited to compromise the integrity and security of the network on the affected system.
Attacker Value
Unknown

CVE-2023-38543

Disclosure Date: November 15, 2023 (last updated November 23, 2023)
A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine.