Show filters
101 Total Results
Displaying 41-50 of 101
Sort by:
Attacker Value
Unknown
CVE-2024-21894
Disclosure Date: April 04, 2024 (last updated April 10, 2024)
A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack. In certain conditions this may lead to execution of arbitrary code
0
Attacker Value
Unknown
CVE-2024-22053
Disclosure Date: April 04, 2024 (last updated April 10, 2024)
A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x
22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack or in certain conditions read contents from memory.
0
Attacker Value
Unknown
CVE-2024-22052
Disclosure Date: April 04, 2024 (last updated April 10, 2024)
A null pointer dereference vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack
0
Attacker Value
Unknown
CVE-2024-22023
Disclosure Date: April 04, 2024 (last updated April 10, 2024)
An XML entity expansion or XEE vulnerability in SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated attacker to send specially crafted XML requests in-order-to temporarily cause resource exhaustion thereby resulting in a limited-time DoS.
0
Attacker Value
Unknown
CVE-2023-43763
Disclosure Date: September 22, 2023 (last updated October 08, 2023)
Certain WithSecure products allow XSS via an unvalidated parameter in the endpoint. This affects WithSecure Policy Manager 15 on Windows and Linux.
0
Attacker Value
Unknown
CVE-2023-43762
Disclosure Date: September 22, 2023 (last updated October 13, 2023)
Certain WithSecure products allow Unauthenticated Remote Code Execution via the web server (backend). This affects WithSecure Policy Manager 15 and Policy Manager Proxy 15.
0
Attacker Value
Unknown
CVE-2023-39252
Disclosure Date: September 21, 2023 (last updated October 08, 2023)
Dell SCG Policy Manager 5.16.00.14 contains a broken cryptographic algorithm vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by performing MitM attacks and let attackers obtain sensitive information.
0
Attacker Value
Unknown
CVE-2022-34462
Disclosure Date: January 18, 2023 (last updated November 08, 2023)
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a Hard-coded Password Vulnerability. An attacker, with the knowledge of the hard-coded credentials, could potentially exploit this vulnerability to login to the system to gain admin privileges.
0
Attacker Value
Unknown
CVE-2022-34442
Disclosure Date: January 18, 2023 (last updated November 08, 2023)
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain LDAP user privileges.
0
Attacker Value
Unknown
CVE-2022-34441
Disclosure Date: January 11, 2023 (last updated November 08, 2023)
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain admin privileges.
0