Show filters
423 Total Results
Displaying 71-80 of 423
Sort by:
Attacker Value
Unknown

CVE-2024-11634

Disclosure Date: December 10, 2024 (last updated January 18, 2025)
Command injection in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to achieve remote code execution. (Not applicable to 9.1Rx)
Attacker Value
Unknown

CVE-2024-11633

Disclosure Date: December 10, 2024 (last updated January 18, 2025)
Argument injection in Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution
Attacker Value
Unknown

CVE-2024-10256

Disclosure Date: December 10, 2024 (last updated December 21, 2024)
Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.
0
Attacker Value
Unknown

CVE-2024-39712

Disclosure Date: November 13, 2024 (last updated December 01, 2024)
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
0
Attacker Value
Unknown

CVE-2024-39711

Disclosure Date: November 13, 2024 (last updated December 01, 2024)
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
0
Attacker Value
Unknown

CVE-2024-39710

Disclosure Date: November 13, 2024 (last updated December 01, 2024)
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
0
Attacker Value
Unknown

CVE-2024-39709

Disclosure Date: November 13, 2024 (last updated November 23, 2024)
Incorrect file permissions in Ivanti Connect Secure before version 22.6R2 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1 (Not Applicable to 9.1Rx) allow a local authenticated attacker to escalate their privileges.
0
Attacker Value
Unknown

CVE-2024-38656

Disclosure Date: November 13, 2024 (last updated December 01, 2024)
Argument injection in Ivanti Connect Secure before version 22.7R2.2 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
0
Attacker Value
Unknown

CVE-2024-38655

Disclosure Date: November 13, 2024 (last updated November 23, 2024)
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.1 and 9.1R18.9 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
0
Attacker Value
Unknown

CVE-2024-38654

Disclosure Date: November 13, 2024 (last updated November 13, 2024)
Improper bounds checking in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker with admin privileges to cause a denial of service.
0