Show filters
423 Total Results
Displaying 61-70 of 423
Sort by:
Attacker Value
Unknown
CVE-2024-8496
Disclosure Date: December 11, 2024 (last updated December 18, 2024)
Under specific circumstances, insecure permissions in Ivanti Workspace Control before version 10.18.40.0 allows a local authenticated attacker to achieve local privilege escalation.
0
Attacker Value
Unknown
CVE-2024-11598
Disclosure Date: December 11, 2024 (last updated January 24, 2025)
Under specific circumstances, insecure permissions in Ivanti Application Control before version 2024.3 HF1, 2024.1 HF2, or 2023.3 HF3 allows a local authenticated attacker to achieve local privilege escalation.
0
Attacker Value
Unknown
CVE-2024-11597
Disclosure Date: December 11, 2024 (last updated January 24, 2025)
Under specific circumstances, insecure permissions in Ivanti Performance Manager before version 2024.3 HF1, 2024.1 HF1, or 2023.3 HF1 allows a local authenticated attacker to achieve local privilege escalation.
0
Attacker Value
Unknown
CVE-2024-10251
Disclosure Date: December 11, 2024 (last updated December 18, 2024)
Under specific circumstances, insecure permissions in Ivanti Security Controls before version 2024.4.1 allows a local authenticated attacker to achieve local privilege escalation.
0
Attacker Value
Unknown
CVE-2024-9844
Disclosure Date: December 10, 2024 (last updated January 18, 2025)
Insufficient server-side controls in Secure Application Manager of Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker to bypass restrictions.
0
Attacker Value
Unknown
CVE-2024-8540
Disclosure Date: December 10, 2024 (last updated December 21, 2024)
Insecure permissions in Ivanti Sentry before versions 9.20.2 and 10.0.2 or 10.1.0 allow a local authenticated attacker to modify sensitive application components.
0
Attacker Value
Unknown
CVE-2024-7572
Disclosure Date: December 10, 2024 (last updated December 21, 2024)
Insufficient permissions in Ivanti DSM before version 2024.3.5740 allows a local authenticated attacker to delete arbitrary files.
0
Attacker Value
Unknown
CVE-2024-11773
Disclosure Date: December 10, 2024 (last updated January 18, 2025)
SQL injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
0
Attacker Value
Unknown
CVE-2024-11772
Disclosure Date: December 10, 2024 (last updated January 18, 2025)
Command injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
0
Attacker Value
Unknown
CVE-2024-11639
Disclosure Date: December 10, 2024 (last updated January 18, 2025)
An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access
0