Show filters
423 Total Results
Displaying 31-40 of 423
Sort by:
Attacker Value
Unknown

CVE-2024-13842

Disclosure Date: February 11, 2025 (last updated February 21, 2025)
A hardcoded key in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.
Attacker Value
Unknown

CVE-2024-13830

Disclosure Date: February 11, 2025 (last updated February 14, 2025)
Reflected XSS in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required.
Attacker Value
Unknown

CVE-2024-13813

Disclosure Date: February 11, 2025 (last updated February 21, 2025)
Insufficient permissions in Ivanti Secure Access Client before version 22.8R1 allows a local authenticated attacker to delete arbitrary files.
Attacker Value
Unknown

CVE-2024-12058

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
External control of a file name in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to read arbitrary files.
0
Attacker Value
Unknown

CVE-2024-11771

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Path traversal in Ivanti CSA before version 5.0.5 allows a remote unauthenticated attacker to access restricted functionality.
0
Attacker Value
Unknown

CVE-2024-10644

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
0
Attacker Value
Unknown

CVE-2024-13172

Disclosure Date: January 14, 2025 (last updated January 15, 2025)
Improper signature verification in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required.
0
Attacker Value
Unknown

CVE-2024-13171

Disclosure Date: January 14, 2025 (last updated January 15, 2025)
Insufficient filename validation in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required.
0
Attacker Value
Unknown

CVE-2024-13170

Disclosure Date: January 14, 2025 (last updated January 15, 2025)
An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.
0
Attacker Value
Unknown

CVE-2024-13169

Disclosure Date: January 14, 2025 (last updated January 15, 2025)
An out-of-bounds read in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a local authenticated attacker to escalate their privileges.
0