Show filters
101 Total Results
Displaying 41-50 of 101
Sort by:
Attacker Value
Unknown

CVE-2024-21894

Disclosure Date: April 04, 2024 (last updated April 10, 2024)
A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack. In certain conditions this may lead to execution of arbitrary code
Attacker Value
Unknown

CVE-2024-22053

Disclosure Date: April 04, 2024 (last updated April 10, 2024)
A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack or in certain conditions read contents from memory.
Attacker Value
Unknown

CVE-2024-22052

Disclosure Date: April 04, 2024 (last updated April 10, 2024)
A null pointer dereference vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack
Attacker Value
Unknown

CVE-2024-22023

Disclosure Date: April 04, 2024 (last updated April 10, 2024)
An XML entity expansion or XEE vulnerability in SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated attacker to send specially crafted XML requests in-order-to temporarily cause resource exhaustion thereby resulting in a limited-time DoS.
Attacker Value
Unknown

CVE-2023-43763

Disclosure Date: September 22, 2023 (last updated October 08, 2023)
Certain WithSecure products allow XSS via an unvalidated parameter in the endpoint. This affects WithSecure Policy Manager 15 on Windows and Linux.
Attacker Value
Unknown

CVE-2023-43762

Disclosure Date: September 22, 2023 (last updated October 13, 2023)
Certain WithSecure products allow Unauthenticated Remote Code Execution via the web server (backend). This affects WithSecure Policy Manager 15 and Policy Manager Proxy 15.
Attacker Value
Unknown

CVE-2023-39252

Disclosure Date: September 21, 2023 (last updated October 08, 2023)
Dell SCG Policy Manager 5.16.00.14 contains a broken cryptographic algorithm vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by performing MitM attacks and let attackers obtain sensitive information.
Attacker Value
Unknown

CVE-2022-34462

Disclosure Date: January 18, 2023 (last updated November 08, 2023)
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a Hard-coded Password Vulnerability. An attacker, with the knowledge of the hard-coded credentials, could potentially exploit this vulnerability to login to the system to gain admin privileges.
Attacker Value
Unknown

CVE-2022-34442

Disclosure Date: January 18, 2023 (last updated November 08, 2023)
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability.  An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain LDAP user privileges.
Attacker Value
Unknown

CVE-2022-34441

Disclosure Date: January 11, 2023 (last updated November 08, 2023)
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain admin privileges.