ivanti CVE Vulnerabilities & Metrics

Focus on ivanti vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About ivanti Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with ivanti. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total ivanti CVEs: 307
Earliest CVE date: 26 May 2016, 14:59 UTC
Latest CVE date: 11 Feb 2025, 16:15 UTC

Latest CVE reference: CVE-2025-22467

Rolling Stats

30-day Count (Rolling): 6
365-day Count (Rolling): 110

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 20.0%
Year Variation (Calendar): 35.8%

Month Growth Rate (30-day Rolling): 20.0%
Year Growth Rate (365-day Rolling): 35.8%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical ivanti CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 2.04

Max CVSS: 10.0

Critical CVEs (≥9): 6

CVSS Range vs. Count

Range Count
0.0-3.9 210
4.0-6.9 71
7.0-8.9 20
9.0-10.0 6

CVSS Distribution Chart

Top 5 Highest CVSS ivanti CVEs

These are the five CVEs with the highest CVSS scores for ivanti, sorted by severity first and recency.

All CVEs for ivanti

CVE-2025-22467 ivanti vulnerability CVSS: 0 11 Feb 2025, 16:15 UTC

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authenticated attacker to achieve remote code execution.

CVE-2024-47908 ivanti vulnerability CVSS: 0 11 Feb 2025, 16:15 UTC

OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVE-2024-13843 ivanti vulnerability CVSS: 0 11 Feb 2025, 16:15 UTC

Cleartext storage of information in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.

CVE-2024-13842 ivanti vulnerability CVSS: 0 11 Feb 2025, 16:15 UTC

A hardcoded key in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.

CVE-2024-13830 ivanti vulnerability CVSS: 0 11 Feb 2025, 16:15 UTC

Reflected XSS in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required.

CVE-2024-13813 ivanti vulnerability CVSS: 0 11 Feb 2025, 16:15 UTC

Insufficient permissions in Ivanti Secure Access Client before version 22.8R1 allows a local authenticated attacker to delete arbitrary files.

CVE-2024-13181 ivanti vulnerability CVSS: 0 14 Jan 2025, 17:15 UTC

Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication. This CVE addresses incomplete fixes from CVE-2024-47010.

CVE-2024-13180 ivanti vulnerability CVSS: 0 14 Jan 2025, 17:15 UTC

Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to leak sensitive information. This CVE addresses incomplete fixes from CVE-2024-47011.

CVE-2024-13179 ivanti vulnerability CVSS: 0 14 Jan 2025, 17:15 UTC

Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication.

CVE-2025-0283 ivanti vulnerability CVSS: 0 08 Jan 2025, 23:15 UTC

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a local authenticated attacker to escalate their privileges.

CVE-2025-0282 ivanti vulnerability CVSS: 0 08 Jan 2025, 23:15 UTC

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.

CVE-2024-9845 ivanti vulnerability CVSS: 0 11 Dec 2024, 17:15 UTC

Under specific circumstances, insecure permissions in Ivanti Automation before version 2024.4.0.1 allows a local authenticated attacker to achieve local privilege escalation.

CVE-2024-11598 ivanti vulnerability CVSS: 0 11 Dec 2024, 17:15 UTC

Under specific circumstances, insecure permissions in Ivanti Application Control before version 2024.3 HF1, 2024.1 HF2, or 2023.3 HF3 allows a local authenticated attacker to achieve local privilege escalation.

CVE-2024-11597 ivanti vulnerability CVSS: 0 11 Dec 2024, 17:15 UTC

Under specific circumstances, insecure permissions in Ivanti Performance Manager before version 2024.3 HF1, 2024.1 HF1, or 2023.3 HF1 allows a local authenticated attacker to achieve local privilege escalation.

CVE-2024-9844 ivanti vulnerability CVSS: 0 10 Dec 2024, 19:15 UTC

Insufficient server-side controls in Secure Application Manager of Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker to bypass restrictions.

CVE-2024-11773 ivanti vulnerability CVSS: 0 10 Dec 2024, 19:15 UTC

SQL injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.

CVE-2024-11772 ivanti vulnerability CVSS: 0 10 Dec 2024, 19:15 UTC

Command injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVE-2024-11639 ivanti vulnerability CVSS: 0 10 Dec 2024, 19:15 UTC

An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access

CVE-2024-11634 ivanti vulnerability CVSS: 0 10 Dec 2024, 19:15 UTC

Command injection in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to achieve remote code execution. (Not applicable to 9.1Rx)

CVE-2024-11633 ivanti vulnerability CVSS: 0 10 Dec 2024, 19:15 UTC

Argument injection in Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution

CVE-2024-37398 ivanti vulnerability CVSS: 0 13 Nov 2024, 02:15 UTC

Insufficient validation in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.

CVE-2024-29211 ivanti vulnerability CVSS: 0 13 Nov 2024, 02:15 UTC

A race condition in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to modify sensitive configuration files.

CVE-2024-9843 ivanti vulnerability CVSS: 0 12 Nov 2024, 17:15 UTC

A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denial of service.

CVE-2024-9842 ivanti vulnerability CVSS: 0 12 Nov 2024, 17:15 UTC

Incorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to create arbitrary folders.

CVE-2024-8539 ivanti vulnerability CVSS: 0 12 Nov 2024, 17:15 UTC

Improper authorization in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker to modify sensitive configuration files.

CVE-2024-7571 ivanti vulnerability CVSS: 0 12 Nov 2024, 17:15 UTC

Incorrect permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.

CVE-2024-11006 ivanti vulnerability CVSS: 0 12 Nov 2024, 17:15 UTC

Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVE-2024-11005 ivanti vulnerability CVSS: 0 12 Nov 2024, 17:15 UTC

Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVE-2024-11004 ivanti vulnerability CVSS: 0 12 Nov 2024, 17:15 UTC

Reflected XSS in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required.

CVE-2024-9420 ivanti vulnerability CVSS: 0 12 Nov 2024, 16:15 UTC

A use-after-free in Ivanti Connect Secure before version 22.7R2.3 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker to achieve remote code execution

CVE-2024-8495 ivanti vulnerability CVSS: 0 12 Nov 2024, 16:15 UTC

A null pointer dereference in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote unauthenticated attacker to cause a denial of service.

CVE-2024-50331 ivanti vulnerability CVSS: 0 12 Nov 2024, 16:15 UTC

An out-of-bounds read vulnerability in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to leak sensitive information in memory.

CVE-2024-50329 ivanti vulnerability CVSS: 0 12 Nov 2024, 16:15 UTC

Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.

CVE-2024-50328 ivanti vulnerability CVSS: 0 12 Nov 2024, 16:15 UTC

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVE-2024-50327 ivanti vulnerability CVSS: 0 12 Nov 2024, 16:15 UTC

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVE-2024-50326 ivanti vulnerability CVSS: 0 12 Nov 2024, 16:15 UTC

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVE-2024-50324 ivanti vulnerability CVSS: 0 12 Nov 2024, 16:15 UTC

Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVE-2024-50323 ivanti vulnerability CVSS: 0 12 Nov 2024, 16:15 UTC

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated attacker to achieve code execution. User interaction is required.

CVE-2024-50322 ivanti vulnerability CVSS: 0 12 Nov 2024, 16:15 UTC

Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated attacker to achieve code execution. User interaction is required.

CVE-2024-50321 ivanti vulnerability CVSS: 0 12 Nov 2024, 16:15 UTC

An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.

CVE-2024-50320 ivanti vulnerability CVSS: 0 12 Nov 2024, 16:15 UTC

An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.

CVE-2024-50319 ivanti vulnerability CVSS: 0 12 Nov 2024, 16:15 UTC

An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.

CVE-2024-50318 ivanti vulnerability CVSS: 0 12 Nov 2024, 16:15 UTC

A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.

CVE-2024-50317 ivanti vulnerability CVSS: 0 12 Nov 2024, 16:15 UTC

A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.

CVE-2024-47909 ivanti vulnerability CVSS: 0 12 Nov 2024, 16:15 UTC

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.

CVE-2024-47907 ivanti vulnerability CVSS: 0 12 Nov 2024, 16:15 UTC

A stack-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to cause a denial of service.

CVE-2024-47906 ivanti vulnerability CVSS: 0 12 Nov 2024, 16:15 UTC

Excessive binary privileges in Ivanti Connect Secure before version 22.7R2.3 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.2 (Not Applicable to 9.1Rx) allows a local authenticated attacker to escalate privileges.

CVE-2024-47905 ivanti vulnerability CVSS: 0 12 Nov 2024, 16:15 UTC

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.

CVE-2024-11007 ivanti vulnerability CVSS: 0 12 Nov 2024, 16:15 UTC

Command injection in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVE-2024-9381 ivanti vulnerability CVSS: 0 08 Oct 2024, 17:15 UTC

Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.

CVE-2024-9380 ivanti vulnerability CVSS: 0 08 Oct 2024, 17:15 UTC

An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution.

CVE-2024-9379 ivanti vulnerability CVSS: 0 08 Oct 2024, 17:15 UTC

SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.

CVE-2024-7612 ivanti vulnerability CVSS: 0 08 Oct 2024, 17:15 UTC

Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application components.

CVE-2024-47011 ivanti vulnerability CVSS: 0 08 Oct 2024, 17:15 UTC

Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information

CVE-2024-47010 ivanti vulnerability CVSS: 0 08 Oct 2024, 17:15 UTC

Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.

CVE-2024-47009 ivanti vulnerability CVSS: 0 08 Oct 2024, 17:15 UTC

Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.

CVE-2024-47008 ivanti vulnerability CVSS: 0 08 Oct 2024, 17:15 UTC

Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information.

CVE-2024-47007 ivanti vulnerability CVSS: 0 08 Oct 2024, 17:15 UTC

A NULL pointer dereference in WLAvalancheService.exe of Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to cause a denial of service.

CVE-2024-8963 ivanti vulnerability CVSS: 0 19 Sep 2024, 18:15 UTC

Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.

CVE-2024-34785 ivanti vulnerability CVSS: 0 12 Sep 2024, 02:15 UTC

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVE-2024-34783 ivanti vulnerability CVSS: 0 12 Sep 2024, 02:15 UTC

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVE-2024-34779 ivanti vulnerability CVSS: 0 12 Sep 2024, 02:15 UTC

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVE-2024-32848 ivanti vulnerability CVSS: 0 12 Sep 2024, 02:15 UTC

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVE-2024-32846 ivanti vulnerability CVSS: 0 12 Sep 2024, 02:15 UTC

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVE-2024-32845 ivanti vulnerability CVSS: 0 12 Sep 2024, 02:15 UTC

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVE-2024-32843 ivanti vulnerability CVSS: 0 12 Sep 2024, 02:15 UTC

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVE-2024-32842 ivanti vulnerability CVSS: 0 12 Sep 2024, 02:15 UTC

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVE-2024-32840 ivanti vulnerability CVSS: 0 12 Sep 2024, 02:15 UTC

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVE-2024-29847 ivanti vulnerability CVSS: 0 12 Sep 2024, 02:15 UTC

Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.

CVE-2024-8441 ivanti vulnerability CVSS: 0 10 Sep 2024, 21:15 UTC

An uncontrolled search path in the agent of Ivanti EPM before 2022 SU6, or the 2024 September update allows a local authenticated attacker with admin privileges to escalate their privileges to SYSTEM.

CVE-2024-8322 ivanti vulnerability CVSS: 0 10 Sep 2024, 21:15 UTC

Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker to access restricted functionality.

CVE-2024-8321 ivanti vulnerability CVSS: 0 10 Sep 2024, 21:15 UTC

Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to isolate managed devices from the network.

CVE-2024-8320 ivanti vulnerability CVSS: 0 10 Sep 2024, 21:15 UTC

Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to spoof Network Isolation status of managed devices.

CVE-2024-8191 ivanti vulnerability CVSS: 0 10 Sep 2024, 21:15 UTC

SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.

CVE-2024-8190 ivanti vulnerability CVSS: 0 10 Sep 2024, 21:15 UTC

An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.

CVE-2024-8012 ivanti vulnerability CVSS: 0 10 Sep 2024, 21:15 UTC

An authentication bypass weakness in the message broker service of Ivanti Workspace Control version 10.18.0.0 and below allows a local authenticated attacker to escalate their privileges.

CVE-2024-44107 ivanti vulnerability CVSS: 0 10 Sep 2024, 21:15 UTC

DLL hijacking in the management console of Ivanti Workspace Control version 10.18.0.0 and below allows a local authenticated attacker to escalate their privileges and achieve arbitrary code execution.

CVE-2024-44106 ivanti vulnerability CVSS: 0 10 Sep 2024, 21:15 UTC

Insufficient server-side controls in the management console of Ivanti Workspace Control version 10.18.0.0 and below allows a local authenticated attacker to escalate their privileges.

CVE-2024-44105 ivanti vulnerability CVSS: 0 10 Sep 2024, 21:15 UTC

Cleartext transmission of sensitive information in the management console of Ivanti Workspace Control version 10.18.0.0 and below allows a local authenticated attacker to obtain OS credentials.

CVE-2024-44104 ivanti vulnerability CVSS: 0 10 Sep 2024, 21:15 UTC

An incorrectly implemented authentication scheme that is subjected to a spoofing attack in the management console of Ivanti Workspace Control version 10.18.0.0 and below allows a local authenticated attacker to escalate their privileges.

CVE-2024-44103 ivanti vulnerability CVSS: 0 10 Sep 2024, 21:15 UTC

DLL hijacking in the management console of Ivanti Workspace Control version 10.18.0.0 and below allows a local authenticated attacker to escalate their privileges.

CVE-2024-38653 ivanti vulnerability CVSS: 0 14 Aug 2024, 03:15 UTC

XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.

CVE-2024-38652 ivanti vulnerability CVSS: 0 14 Aug 2024, 03:15 UTC

Path traversal in the skin management component of Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to achieve denial of service via arbitrary file deletion.

CVE-2024-37399 ivanti vulnerability CVSS: 0 14 Aug 2024, 03:15 UTC

A NULL pointer dereference in WLAvalancheService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS.

CVE-2024-37373 ivanti vulnerability CVSS: 0 14 Aug 2024, 03:15 UTC

Improper input validation in the Central Filestore in Ivanti Avalanche 6.3.1 allows a remote authenticated attacker with admin rights to achieve RCE.

CVE-2024-36136 ivanti vulnerability CVSS: 0 14 Aug 2024, 03:15 UTC

An off-by-one error in WLInfoRailService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS.

CVE-2024-7593 ivanti vulnerability CVSS: 0 13 Aug 2024, 19:15 UTC

Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.

CVE-2024-7570 ivanti vulnerability CVSS: 0 13 Aug 2024, 19:15 UTC

Improper certificate validation in Ivanti ITSM on-prem and Neurons for ITSM Versions 2023.4 and earlier allows a remote attacker in a MITM position to craft a token that would allow access to ITSM as any user.

CVE-2024-7569 ivanti vulnerability CVSS: 0 13 Aug 2024, 19:15 UTC

An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the OIDC client secret via debug information.

CVE-2024-36132 ivanti vulnerability CVSS: 0 07 Aug 2024, 04:17 UTC

Insufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authentication and access sensitive resources.

CVE-2024-36131 ivanti vulnerability CVSS: 0 07 Aug 2024, 04:17 UTC

An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary commands on the underlying operating system of the appliance.

CVE-2024-36130 ivanti vulnerability CVSS: 0 07 Aug 2024, 04:17 UTC

An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute arbitrary commands on the underlying operating system of the appliance.

CVE-2024-34788 ivanti vulnerability CVSS: 0 07 Aug 2024, 04:17 UTC

An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to access potentially sensitive information

CVE-2024-29846 ivanti vulnerability CVSS: 0 31 May 2024, 18:15 UTC

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.

CVE-2024-29830 ivanti vulnerability CVSS: 0 31 May 2024, 18:15 UTC

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.

CVE-2024-29829 ivanti vulnerability CVSS: 0 31 May 2024, 18:15 UTC

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.

CVE-2024-29828 ivanti vulnerability CVSS: 0 31 May 2024, 18:15 UTC

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.

CVE-2024-29827 ivanti vulnerability CVSS: 0 31 May 2024, 18:15 UTC

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

CVE-2024-29826 ivanti vulnerability CVSS: 0 31 May 2024, 18:15 UTC

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

CVE-2024-29825 ivanti vulnerability CVSS: 0 31 May 2024, 18:15 UTC

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

CVE-2024-29824 ivanti vulnerability CVSS: 0 31 May 2024, 18:15 UTC

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

CVE-2024-29823 ivanti vulnerability CVSS: 0 31 May 2024, 18:15 UTC

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

CVE-2024-29822 ivanti vulnerability CVSS: 0 31 May 2024, 18:15 UTC

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

CVE-2024-22026 ivanti vulnerability CVSS: 0 22 May 2024, 23:15 UTC

A local privilege escalation vulnerability in EPMM before 12.1.0.0 allows an authenticated local user to bypass shell restriction and execute arbitrary commands on the appliance.

CVE-2024-21894 ivanti vulnerability CVSS: 0 04 Apr 2024, 23:15 UTC

A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack. In certain conditions this may lead to execution of arbitrary code

CVE-2024-22053 ivanti vulnerability CVSS: 0 04 Apr 2024, 20:15 UTC

A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack or in certain conditions read contents from memory.

CVE-2024-22052 ivanti vulnerability CVSS: 0 04 Apr 2024, 20:15 UTC

A null pointer dereference vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack

CVE-2024-22023 ivanti vulnerability CVSS: 0 04 Apr 2024, 20:15 UTC

An XML entity expansion or XEE vulnerability in SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated attacker to send specially crafted XML requests in-order-to temporarily cause resource exhaustion thereby resulting in a limited-time DoS.

CVE-2023-46808 ivanti vulnerability CVSS: 0 31 Mar 2024, 02:15 UTC

An file upload vulnerability in Ivanti ITSM before 2023.4, allows an authenticated remote user to perform file writes to the server. Successful exploitation may lead to execution of commands in the context of non-root user.

CVE-2023-41724 ivanti vulnerability CVSS: 0 31 Mar 2024, 02:15 UTC

A command injection vulnerability in Ivanti Sentry prior to 9.19.0 allows unauthenticated threat actor to execute arbitrary commands on the underlying operating system of the appliance within the same physical or logical network.

CVE-2024-22024 ivanti vulnerability CVSS: 0 13 Feb 2024, 04:15 UTC

An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.

CVE-2024-21893 ivanti vulnerability CVSS: 0 31 Jan 2024, 18:15 UTC

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.

CVE-2024-21888 ivanti vulnerability CVSS: 0 31 Jan 2024, 18:15 UTC

A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elevate privileges to that of an administrator.

CVE-2023-41474 ivanti vulnerability CVSS: 0 25 Jan 2024, 20:15 UTC

Directory Traversal vulnerability in Ivanti Avalanche 6.3.4.153 allows a remote authenticated attacker to obtain sensitive information via the javax.faces.resource component.

CVE-2024-21887 ivanti vulnerability CVSS: 0 12 Jan 2024, 17:15 UTC

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.

CVE-2023-46805 ivanti vulnerability CVSS: 0 12 Jan 2024, 17:15 UTC

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

CVE-2023-39336 ivanti vulnerability CVSS: 0 09 Jan 2024, 02:15 UTC

An unspecified SQL Injection vulnerability in Ivanti Endpoint Manager released prior to 2022 SU 5 allows an attacker with access to the internal network to execute arbitrary SQL queries and retrieve output without the need for authentication. Under specific circumstances, this may also lead to RCE on the core server.

CVE-2023-46804 ivanti vulnerability CVSS: 0 19 Dec 2023, 16:15 UTC

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS).

CVE-2023-46803 ivanti vulnerability CVSS: 0 19 Dec 2023, 16:15 UTC

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS).

CVE-2023-46266 ivanti vulnerability CVSS: 0 19 Dec 2023, 16:15 UTC

An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack.

CVE-2023-46265 ivanti vulnerability CVSS: 0 19 Dec 2023, 16:15 UTC

An unauthenticated could abuse a XXE vulnerability in the Smart Device Server to leak data or perform a Server-Side Request Forgery (SSRF).

CVE-2023-46264 ivanti vulnerability CVSS: 0 19 Dec 2023, 16:15 UTC

An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution.

CVE-2023-46263 ivanti vulnerability CVSS: 0 19 Dec 2023, 16:15 UTC

An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remote code execution.

CVE-2023-46262 ivanti vulnerability CVSS: 0 19 Dec 2023, 16:15 UTC

An unauthenticated attacked could send a specifically crafted web request causing a Server-Side Request Forgery (SSRF) in Ivanti Avalanche Remote Control server.

CVE-2023-46261 ivanti vulnerability CVSS: 0 19 Dec 2023, 16:15 UTC

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

CVE-2023-46260 ivanti vulnerability CVSS: 0 19 Dec 2023, 16:15 UTC

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

CVE-2023-46259 ivanti vulnerability CVSS: 0 19 Dec 2023, 16:15 UTC

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

CVE-2023-46258 ivanti vulnerability CVSS: 0 19 Dec 2023, 16:15 UTC

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

CVE-2023-46257 ivanti vulnerability CVSS: 0 19 Dec 2023, 16:15 UTC

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

CVE-2023-46225 ivanti vulnerability CVSS: 0 19 Dec 2023, 16:15 UTC

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

CVE-2023-46224 ivanti vulnerability CVSS: 0 19 Dec 2023, 16:15 UTC

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

CVE-2023-46223 ivanti vulnerability CVSS: 0 19 Dec 2023, 16:15 UTC

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

CVE-2023-46222 ivanti vulnerability CVSS: 0 19 Dec 2023, 16:15 UTC

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

CVE-2023-46221 ivanti vulnerability CVSS: 0 19 Dec 2023, 16:15 UTC

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

CVE-2023-46220 ivanti vulnerability CVSS: 0 19 Dec 2023, 16:15 UTC

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

CVE-2023-46217 ivanti vulnerability CVSS: 0 19 Dec 2023, 16:15 UTC

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

CVE-2023-46216 ivanti vulnerability CVSS: 0 19 Dec 2023, 16:15 UTC

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

CVE-2023-41727 ivanti vulnerability CVSS: 0 19 Dec 2023, 16:15 UTC

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

CVE-2021-22962 ivanti vulnerability CVSS: 0 19 Dec 2023, 16:15 UTC

An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack.

CVE-2023-39340 ivanti vulnerability CVSS: 0 16 Dec 2023, 02:15 UTC

A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker can send a specific request which may lead to Denial of Service (DoS) of the appliance.

CVE-2023-41720 ivanti vulnerability CVSS: 0 14 Dec 2023, 02:15 UTC

A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker with a foothold on an Ivanti Connect Secure (ICS) appliance can escalate their privileges by exploiting a vulnerable installed application. This vulnerability allows the attacker to gain elevated execution privileges on the affected system.

CVE-2023-41719 ivanti vulnerability CVSS: 0 14 Dec 2023, 02:15 UTC

A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker impersonating an administrator may craft a specific web request which may lead to remote code execution.

CVE-2023-41718 ivanti vulnerability CVSS: 0 15 Nov 2023, 00:15 UTC

When a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the affected system when having control over a specific file.

CVE-2023-39337 ivanti vulnerability CVSS: 0 15 Nov 2023, 00:15 UTC

A security vulnerability in EPMM Versions 11.10, 11.9 and 11.8 older allows a threat actor with knowledge of an enrolled device identifier to access and extract sensitive information, including device and environment configuration details, as well as secrets. This vulnerability poses a serious security risk, potentially exposing confidential data and system integrity.

CVE-2023-39335 ivanti vulnerability CVSS: 0 15 Nov 2023, 00:15 UTC

A security vulnerability has been identified in EPMM Versions 11.10, 11.9 and 11.8 and older allowing an unauthenticated threat actor to impersonate any existing user during the device enrollment process. This issue poses a significant security risk, as it enables unauthorized access and potential misuse of user accounts and resources.

CVE-2023-38544 ivanti vulnerability CVSS: 0 15 Nov 2023, 00:15 UTC

A logged in user can modify specific files that may lead to unauthorized changes in system-wide configuration settings. This vulnerability could be exploited to compromise the integrity and security of the network on the affected system.

CVE-2023-38543 ivanti vulnerability CVSS: 0 15 Nov 2023, 00:15 UTC

A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine.

CVE-2023-38043 ivanti vulnerability CVSS: 0 15 Nov 2023, 00:15 UTC

A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine and, in some cases, resulting in a full compromise of the system.

CVE-2023-35080 ivanti vulnerability CVSS: 0 15 Nov 2023, 00:15 UTC

A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to various security risks, including the escalation of privileges, denial of service, or information disclosure.

CVE-2023-41726 ivanti vulnerability CVSS: 0 03 Nov 2023, 20:15 UTC

Ivanti Avalanche Incorrect Default Permissions allows Local Privilege Escalation Vulnerability

CVE-2023-41725 ivanti vulnerability CVSS: 0 03 Nov 2023, 20:15 UTC

Ivanti Avalanche EnterpriseServer Service Unrestricted File Upload Local Privilege Escalation Vulnerability

CVE-2022-44569 ivanti vulnerability CVSS: 0 03 Nov 2023, 20:15 UTC

A locally authenticated attacker with low privileges can bypass authentication due to insecure inter-process communication.

CVE-2022-43555 ivanti vulnerability CVSS: 0 03 Nov 2023, 20:15 UTC

Ivanti Avalanche Printer Device Service Missing Authentication Local Privilege Escalation Vulnerability

CVE-2022-43554 ivanti vulnerability CVSS: 0 03 Nov 2023, 20:15 UTC

Ivanti Avalanche Smart Device Service Missing Authentication Local Privilege Escalation Vulnerability

CVE-2023-38041 ivanti vulnerability CVSS: 0 25 Oct 2023, 18:17 UTC

A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flow is initiated, an attacker can exploit this condition to gain unauthorized elevated privileges on the affected system.

CVE-2023-35084 ivanti vulnerability CVSS: 0 18 Oct 2023, 04:15 UTC

Unsafe Deserialization of User Input could lead to Execution of Unauthorized Operations in Ivanti Endpoint Manager 2022 su3 and all previous versions, which could allow an attacker to execute commands remotely.

CVE-2023-35083 ivanti vulnerability CVSS: 0 18 Oct 2023, 04:15 UTC

Allows an authenticated attacker with network access to read arbitrary files on Endpoint Manager recently discovered on 2022 SU3 and all previous versions potentially leading to the leakage of sensitive information.

CVE-2023-38344 ivanti vulnerability CVSS: 0 21 Sep 2023, 21:15 UTC

An issue was discovered in Ivanti Endpoint Manager before 2022 SU4. A file disclosure vulnerability exists in the GetFileContents SOAP action exposed via /landesk/managementsuite/core/core.secure/OsdScript.asmx. The application does not sufficiently restrict user-supplied paths, allowing for an authenticated attacker to read arbitrary files from a remote system, including the private key used to authenticate to agents for remote access.

CVE-2023-38343 ivanti vulnerability CVSS: 0 21 Sep 2023, 21:15 UTC

An XXE (XML external entity injection) vulnerability exists in the CSEP component of Ivanti Endpoint Manager before 2022 SU4. External entity references are enabled in the XML parser configuration. Exploitation of this vulnerability can lead to file disclosure or Server Side Request Forgery.

CVE-2023-35082 ivanti vulnerability CVSS: 0 15 Aug 2023, 16:15 UTC

An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier.

CVE-2023-32565 ivanti vulnerability CVSS: 0 10 Aug 2023, 20:15 UTC

An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. Fixed in version 6.4.1.

CVE-2023-32564 ivanti vulnerability CVSS: 0 10 Aug 2023, 20:15 UTC

An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution.

CVE-2023-32563 ivanti vulnerability CVSS: 0 10 Aug 2023, 20:15 UTC

An unauthenticated attacker could achieve the code execution through a RemoteControl server.

CVE-2023-32562 ivanti vulnerability CVSS: 0 10 Aug 2023, 20:15 UTC

An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution. Fixed in version 6.4.1.

CVE-2023-32561 ivanti vulnerability CVSS: 0 10 Aug 2023, 20:15 UTC

A previously generated artifact by an administrator could be accessed by an attacker. The contents of this artifact could lead to authentication bypass. Fixed in version 6.4.1.

CVE-2023-32560 ivanti vulnerability CVSS: 0 10 Aug 2023, 20:15 UTC

An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code execution. Thanks to a Researcher at Tenable for finding and reporting. Fixed in version 6.4.1.

CVE-2023-28129 ivanti vulnerability CVSS: 0 10 Aug 2023, 20:15 UTC

DSM 2022.2 SU2 and all prior versions allows a local low privileged account to execute arbitrary OS commands as the DSM software installation user.

CVE-2023-32567 ivanti vulnerability CVSS: 0 10 Aug 2023, 19:15 UTC

Ivanti Avalanche decodeToMap XML External Entity Processing. Fixed in version 6.4.1.236

CVE-2023-32566 ivanti vulnerability CVSS: 0 10 Aug 2023, 19:15 UTC

An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. Fixed in version 6.4.1.

CVE-2023-35081 ivanti vulnerability CVSS: 0 03 Aug 2023, 18:15 UTC

A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) allows an authenticated administrator to write arbitrary files onto the appliance.

CVE-2023-35078 ivanti vulnerability CVSS: 0 25 Jul 2023, 07:15 UTC

An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.

CVE-2023-28324 ivanti vulnerability CVSS: 0 01 Jul 2023, 00:15 UTC

A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege escalation or remote code execution.

CVE-2023-28323 ivanti vulnerability CVSS: 0 01 Jul 2023, 00:15 UTC

A deserialization of untrusted data exists in EPM 2022 Su3 and all prior versions that allows an unauthenticated user to elevate rights. This exploit could potentially be used in conjunction with other OS (Operating System) vulnerabilities to escalate privileges on the machine or be used as a stepping stone to get to other network attached machines.

CVE-2023-28128 ivanti vulnerability CVSS: 0 09 May 2023, 22:15 UTC

An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution.

CVE-2023-28127 ivanti vulnerability CVSS: 0 09 May 2023, 22:15 UTC

A path traversal vulnerability exists in Avalanche version 6.3.x and below that when exploited could result in possible information disclosure.

CVE-2023-28126 ivanti vulnerability CVSS: 0 09 May 2023, 22:15 UTC

An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain access by exploiting the SetUser method or can exploit the Race Condition in the authentication message.

CVE-2023-28125 ivanti vulnerability CVSS: 0 09 May 2023, 22:15 UTC

An improper authentication vulnerability exists in Avalanche Premise versions 6.3.x and below that could allow an attacker to gain access to the server by registering to receive messages from the server and perform an authentication bypass.

CVE-2022-36983 ivanti vulnerability CVSS: 0 29 Mar 2023, 19:15 UTC

This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetSettings class. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-15919.

CVE-2022-36982 ivanti vulnerability CVSS: 0 29 Mar 2023, 19:15 UTC

This vulnerability allows remote attackers to read arbitrary files on affected installations of Ivanti Avalanche 6.3.3.101. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the AgentTaskHandler class. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose stored session cookies, leading to further compromise. Was ZDI-CAN-15967.

CVE-2022-36981 ivanti vulnerability CVSS: 0 29 Mar 2023, 19:15 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.3.101. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the DeviceLogResource class. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-15966.

CVE-2022-36980 ivanti vulnerability CVSS: 0 29 Mar 2023, 19:15 UTC

This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the EnterpriseServer service. The issue results from the lack of proper locking when performing operations during authentication. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-15528.

CVE-2022-36979 ivanti vulnerability CVSS: 0 29 Mar 2023, 19:15 UTC

This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the AvalancheDaoSupport class. A crafted request can trigger execution of SQL queries composed from a user-supplied string. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-15493.

CVE-2022-36978 ivanti vulnerability CVSS: 0 29 Mar 2023, 19:15 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the Notification Server service. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-15448.

CVE-2022-36977 ivanti vulnerability CVSS: 0 29 Mar 2023, 19:15 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the Certificate Management Server service. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-15449.

CVE-2022-36976 ivanti vulnerability CVSS: 0 29 Mar 2023, 19:15 UTC

This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. The specific flaw exists within the GroupDaoImpl class. A crafted request can trigger execution of SQL queries composed from a user-supplied string. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-15333.

CVE-2022-36975 ivanti vulnerability CVSS: 0 29 Mar 2023, 19:15 UTC

This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. The specific flaw exists within the ProfileDaoImpl class. A crafted request can trigger execution of SQL queries composed from a user-supplied string. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-15332.

CVE-2022-36974 ivanti vulnerability CVSS: 0 29 Mar 2023, 19:15 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the Web File Server service. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-15330.

CVE-2022-36973 ivanti vulnerability CVSS: 0 29 Mar 2023, 19:15 UTC

This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the ProfileDaoImpl class. A crafted request can trigger execution of SQL queries composed from a user-supplied string. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-15329.

CVE-2022-36972 ivanti vulnerability CVSS: 0 29 Mar 2023, 19:15 UTC

This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. The specific flaw exists within the ProfileDaoImpl class. A crafted request can trigger execution of SQL queries composed from a user-supplied string. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-15328.

CVE-2022-36971 ivanti vulnerability CVSS: 0 29 Mar 2023, 19:15 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the JwtTokenUtility class. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-15301.

CVE-2022-44574 ivanti vulnerability CVSS: 0 10 Mar 2023, 22:15 UTC

An improper authentication vulnerability exists in Avalanche version 6.3.x and below allows unauthenticated attacker to modify properties on specific port.

CVE-2022-35259 ivanti vulnerability CVSS: 0 05 Dec 2022, 22:15 UTC

XML Injection with Endpoint Manager 2022. 3 and below causing a download of a malicious file to run and possibly execute to gain unauthorized privileges.

CVE-2022-35258 ivanti vulnerability CVSS: 0 05 Dec 2022, 22:15 UTC

An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions prior to 9.1R17 and 22.3R1, and Ivanti Neurons for Zero-Trust Access in versions prior to 22.3R1.

CVE-2022-35254 ivanti vulnerability CVSS: 0 05 Dec 2022, 22:15 UTC

An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions prior to 9.1R17 and 22.3R1, and Ivanti Neurons for Zero-Trust Access in versions prior to 22.3R1.

CVE-2022-27773 ivanti vulnerability CVSS: 0 05 Dec 2022, 22:15 UTC

A privilege escalation vulnerability is identified in Ivanti EPM (LANDesk Management Suite) that allows a user to execute commands with elevated privileges.

CVE-2022-21826 ivanti vulnerability CVSS: 0 30 Sep 2022, 17:15 UTC

Pulse Secure version 9.115 and below may be susceptible to client-side http request smuggling, When the application receives a POST request, it ignores the request's Content-Length header and leaves the POST body on the TCP/TLS socket. This body ends up prefixing the next HTTP request sent down that connection, this means when someone loads website attacker may be able to make browser issue a POST to the application, enabling XSS.

CVE-2022-30121 ivanti vulnerability CVSS: 0 23 Sep 2022, 14:15 UTC

The “LANDesk(R) Management Agent” service exposes a socket and once connected, it is possible to launch commands only for signed executables. This is a security bug that allows a limited user to get escalated admin privileges on their system.

CVE-2021-44720 ivanti vulnerability CVSS: 0 12 Aug 2022, 15:15 UTC

In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is stored in the HTML source code of the "Maintenance > Push Configuration > Targets > Target Name" targets.cgi screen. A read-only administrative user can escalate to a read-write administrative role.

CVE-2022-22572 ivanti vulnerability CVSS: 6.5 11 Apr 2022, 20:15 UTC

A non-admin user with user management permission can escalate his privilege to admin user via password reset functionality. The vulnerability affects Incapptic Connect version < 1.40.1.

CVE-2022-22571 ivanti vulnerability CVSS: 3.5 11 Apr 2022, 20:15 UTC

An authenticated high privileged user can perform a stored XSS attack due to incorrect output encoding in Incapptic connect and affects all current versions.

CVE-2021-30497 ivanti vulnerability CVSS: 5.0 06 Apr 2022, 02:15 UTC

Ivanti Avalanche (Premise) 6.3.2 allows remote unauthenticated users to read arbitrary files via Absolute Path Traversal. The imageFilePath parameter processed by the /AvalancheWeb/image endpoint is not verified to be within the scope of the image folder, e.g., the attacker can obtain sensitive information via the C:/Windows/system32/config/system.sav value.

CVE-2022-21828 ivanti vulnerability CVSS: 6.5 04 Mar 2022, 17:15 UTC

A user with high privilege access to the Incapptic Connect web console can remotely execute code on the Incapptic Connect server using a unspecified attack vector in Incapptic Connect version 1.40.0, 1.39.1, 1.39.0, 1.38.1, 1.38.0, 1.37.1, 1.37.0, 1.36.0, 1.35.5, 1.35.4 and 1.35.3.

CVE-2021-38560 ivanti vulnerability CVSS: 4.3 01 Feb 2022, 16:15 UTC

Ivanti Service Manager 2021.1 allows reflected XSS via the appName parameter associated with ConfigDB calls, such as in RelocateAttachments.aspx.

CVE-2022-21823 ivanti vulnerability CVSS: 2.1 10 Jan 2022, 14:12 UTC

A insecure storage of sensitive information vulnerability exists in Ivanti Workspace Control <2021.2 (10.7.30.0) that could allow an attacker with locally authenticated low privileges to obtain key information due to an unspecified attack vector.

CVE-2019-19138 ivanti vulnerability CVSS: 5.0 15 Dec 2021, 08:15 UTC

Ivanti Workspace Control before 10.4.50.0 allows attackers to degrade integrity.

CVE-2021-44529 ivanti vulnerability CVSS: 7.5 08 Dec 2021, 22:15 UTC

A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).

CVE-2021-42133 ivanti vulnerability CVSS: 5.5 07 Dec 2021, 14:15 UTC

An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform an arbitrary file write.

CVE-2021-42132 ivanti vulnerability CVSS: 6.5 07 Dec 2021, 14:15 UTC

A command Injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary command execution.

CVE-2021-42131 ivanti vulnerability CVSS: 6.5 07 Dec 2021, 14:15 UTC

A SQL Injection vulnerability exists in Ivanti Avalance before 6.3.3 allows an attacker with access to the Inforail Service to perform privilege escalation.

CVE-2021-42130 ivanti vulnerability CVSS: 6.5 07 Dec 2021, 14:15 UTC

A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary code execution.

CVE-2021-42129 ivanti vulnerability CVSS: 6.5 07 Dec 2021, 14:15 UTC

A command injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary command execution.

CVE-2021-42128 ivanti vulnerability CVSS: 7.5 07 Dec 2021, 14:15 UTC

An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 using inforail Service allows Privilege Escalation via Enterprise Server Service.

CVE-2021-42127 ivanti vulnerability CVSS: 7.5 07 Dec 2021, 14:15 UTC

A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 using Inforail Service allows arbitrary code execution via Data Repository Service.

CVE-2021-42126 ivanti vulnerability CVSS: 6.5 07 Dec 2021, 14:15 UTC

An improper authorization control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform privilege escalation.

CVE-2021-42125 ivanti vulnerability CVSS: 6.5 07 Dec 2021, 14:15 UTC

An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to write dangerous files.

CVE-2021-42124 ivanti vulnerability CVSS: 6.5 07 Dec 2021, 14:15 UTC

An improper access control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform a session takeover.

CVE-2021-22965 ivanti vulnerability CVSS: 7.8 19 Nov 2021, 19:15 UTC

A vulnerability in Pulse Connect Secure before 9.1R12.1 could allow an unauthenticated administrator to causes a denial of service when a malformed request is sent to the device.

CVE-2021-36235 ivanti vulnerability CVSS: 4.6 01 Sep 2021, 01:15 UTC

An issue was discovered in Ivanti Workspace Control before 10.6.30.0. A locally authenticated user with low privileges can bypass File and Folder Security by leveraging an unspecified attack vector. As a result, the attacker can start applications with elevated privileges.

CVE-2021-22938 ivanti vulnerability CVSS: 6.5 16 Aug 2021, 19:15 UTC

A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitized web parameter in the administrator web console.

CVE-2021-22937 ivanti vulnerability CVSS: 6.5 16 Aug 2021, 19:15 UTC

A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform a file write via a maliciously crafted archive uploaded in the administrator web interface.

CVE-2021-22936 ivanti vulnerability CVSS: 4.3 16 Aug 2021, 19:15 UTC

A vulnerability in Pulse Connect Secure before 9.1R12 could allow a threat actor to perform a cross-site script attack against an authenticated administrator via an unsanitized web parameter.

CVE-2021-22935 ivanti vulnerability CVSS: 6.5 16 Aug 2021, 19:15 UTC

A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitized web parameter.

CVE-2021-22934 ivanti vulnerability CVSS: 6.5 16 Aug 2021, 19:15 UTC

A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator or compromised Pulse Connect Secure device in a load-balanced configuration to perform a buffer overflow via a malicious crafted web request.

CVE-2021-22933 ivanti vulnerability CVSS: 5.5 16 Aug 2021, 19:15 UTC

A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform an arbitrary file delete via a maliciously crafted web request.

CVE-2021-3540 ivanti vulnerability CVSS: 9.0 22 Jul 2021, 19:15 UTC

By abusing the 'install rpm info detail' command, an attacker can escape the restricted clish shell on affected versions of Ivanti MobileIron Core. This issue was fixed in version 11.1.0.0.

CVE-2021-3198 ivanti vulnerability CVSS: 9.0 22 Jul 2021, 19:15 UTC

By abusing the 'install rpm url' command, an attacker can escape the restricted clish shell on affected versions of Ivanti MobileIron Core. This issue was fixed in version 11.1.0.0.

CVE-2021-22908 ivanti vulnerability CVSS: 9.0 27 May 2021, 12:15 UTC

A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to browse SMB shares to execute arbitrary code as the root user. As of version 9.1R3, this permission is not enabled by default.

CVE-2021-22900 ivanti vulnerability CVSS: 6.5 27 May 2021, 12:15 UTC

A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.

CVE-2021-22899 ivanti vulnerability CVSS: 6.5 27 May 2021, 12:15 UTC

A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execution via Windows Resource Profiles Feature

CVE-2021-22894 ivanti vulnerability CVSS: 9.0 27 May 2021, 12:15 UTC

A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as the root user via maliciously crafted meeting room.

CVE-2021-22893 ivanti vulnerability CVSS: 7.5 23 Apr 2021, 17:15 UTC

Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code execution on the Pulse Connect Secure gateway. This vulnerability has been exploited in the wild.

CVE-2020-13773 ivanti vulnerability CVSS: 3.5 16 Nov 2020, 16:15 UTC

Ivanti Endpoint Manager through 2020.1.1 allows XSS via /LDMS/frm_splitfrm.aspx, /LDMS/licensecheck.aspx, /LDMS/frm_splitcollapse.aspx, /LDMS/alert_log.aspx, /LDMS/ServerList.aspx, /LDMS/frm_coremainfrm.aspx, /LDMS/frm_findfrm.aspx, /LDMS/frm_taskfrm.aspx, and /LDMS/query_browsecomp.aspx.

CVE-2020-13772 ivanti vulnerability CVSS: 5.0 16 Nov 2020, 16:15 UTC

In /ldclient/ldprov.cgi in Ivanti Endpoint Manager through 2020.1.1, an attacker is able to disclose information about the server operating system, local pathnames, and environment variables with no authentication required.

CVE-2020-13769 ivanti vulnerability CVSS: 6.5 16 Nov 2020, 16:15 UTC

LDMS/alert_log.aspx in Ivanti Endpoint Manager through 2020.1 allows SQL Injection via a /remotecontrolauth/api/device request.

CVE-2020-13774 ivanti vulnerability CVSS: 9.0 12 Nov 2020, 20:15 UTC

An unrestricted file-upload issue in EditLaunchPadDialog.aspx in Ivanti Endpoint Manager 2019.1 and 2020.1 allows an authenticated attacker to gain remote code execution by uploading a malicious aspx file. The issue is caused by insufficient file extension validation and insecure file operations on the uploaded image, which upon failure will leave the temporarily created files in an accessible location on the server.

CVE-2020-13771 ivanti vulnerability CVSS: 6.9 12 Nov 2020, 18:15 UTC

Various components in Ivanti Endpoint Manager through 2020.1.1 rely on Windows search order when loading a (nonexistent) library file, allowing (under certain conditions) one to gain code execution (and elevation of privileges to the level of privilege held by the vulnerable component such as NT AUTHORITY\SYSTEM) via DLL hijacking. This affects ldiscn32.exe, IpmiRedirectionService.exe, LDAPWhoAmI.exe, and ldprofile.exe.

CVE-2020-13770 ivanti vulnerability CVSS: 7.2 12 Nov 2020, 18:15 UTC

Several services are accessing named pipes in Ivanti Endpoint Manager through 2020.1.1 with default or overly permissive security attributes; as these services run as user ‘NT AUTHORITY\SYSTEM’, the issue can be used to escalate privileges from a local standard or service account having SeImpersonatePrivilege (eg. user ‘NT AUTHORITY\NETWORK SERVICE’).

CVE-2020-8262 ivanti vulnerability CVSS: 4.3 28 Oct 2020, 13:15 UTC

A vulnerability in the Pulse Connect Secure / Pulse Policy Secure below 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) and Open Redirection for authenticated user web interface.

CVE-2020-8261 ivanti vulnerability CVSS: 4.3 28 Oct 2020, 13:15 UTC

A vulnerability in the Pulse Connect Secure / Pulse Policy Secure < 9.1R9 is vulnerable to arbitrary cookie injection.

CVE-2020-8260 ivanti vulnerability CVSS: 6.5 28 Oct 2020, 13:15 UTC

A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction.

CVE-2020-15352 ivanti vulnerability CVSS: 6.5 27 Oct 2020, 05:15 UTC

An XML external entity (XXE) vulnerability in Pulse Connect Secure (PCS) before 9.1R9 and Pulse Policy Secure (PPS) before 9.1R9 allows remote authenticated admins to conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.

CVE-2020-8256 ivanti vulnerability CVSS: 4.0 30 Sep 2020, 18:15 UTC

A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to gain arbitrary file reading access through Pulse Collaboration via XML External Entity (XXE) vulnerability.

CVE-2020-8243 ivanti vulnerability CVSS: 6.5 30 Sep 2020, 18:15 UTC

A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform an arbitrary code execution.

CVE-2020-8238 ivanti vulnerability CVSS: 4.3 30 Sep 2020, 18:15 UTC

A vulnerability in the authenticated user web interface of Pulse Connect Secure and Pulse Policy Secure < 9.1R8.2 could allow attackers to conduct Cross-Site Scripting (XSS).

CVE-2020-13793 ivanti vulnerability CVSS: 7.5 06 Aug 2020, 19:15 UTC

Unsafe storage of AD credentials in Ivanti DSM netinst 5.1 due to a static, hard-coded encryption key.

CVE-2020-12441 ivanti vulnerability CVSS: 10.0 06 Aug 2020, 19:15 UTC

Denial-of-Service (DoS) in Ivanti Service Manager HEAT Remote Control 7.4 due to a buffer overflow in the protocol parser of the ‘HEATRemoteService’ agent. The DoS can be triggered by sending a specially crafted network packet.

CVE-2020-8222 ivanti vulnerability CVSS: 4.0 30 Jul 2020, 13:15 UTC

A path traversal vulnerability exists in Pulse Connect Secure <9.1R8 that allowed an authenticated attacker via the administrator web interface to perform an arbitrary file reading vulnerability through Meeting.

CVE-2020-8221 ivanti vulnerability CVSS: 4.0 30 Jul 2020, 13:15 UTC

A path traversal vulnerability exists in Pulse Connect Secure <9.1R8 which allows an authenticated attacker to read arbitrary files via the administrator web interface.

CVE-2020-8220 ivanti vulnerability CVSS: 5.5 30 Jul 2020, 13:15 UTC

A denial of service vulnerability exists in Pulse Connect Secure <9.1R8 that allows an authenticated attacker to perform command injection via the administrator web which can cause DOS.

CVE-2020-8219 ivanti vulnerability CVSS: 4.0 30 Jul 2020, 13:15 UTC

An insufficient permission check vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to change the password of a full administrator.

CVE-2020-8218 ivanti vulnerability CVSS: 6.5 30 Jul 2020, 13:15 UTC

A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.

CVE-2020-8217 ivanti vulnerability CVSS: 3.5 30 Jul 2020, 13:15 UTC

A cross site scripting (XSS) vulnerability in Pulse Connect Secure <9.1R8 allowed attackers to exploit in the URL used for Citrix ICA.

CVE-2020-8216 ivanti vulnerability CVSS: 4.0 30 Jul 2020, 13:15 UTC

An information disclosure vulnerability in meeting of Pulse Connect Secure <9.1R8 allowed an authenticated end-users to find meeting details, if they know the Meeting ID.

CVE-2020-8206 ivanti vulnerability CVSS: 6.8 30 Jul 2020, 13:15 UTC

An improper authentication vulnerability exists in Pulse Connect Secure <9.1RB that allows an attacker with a users primary credentials to bypass the Google TOTP.

CVE-2020-8204 ivanti vulnerability CVSS: 4.3 30 Jul 2020, 13:15 UTC

A cross site scripting (XSS) vulnerability exists in Pulse Connect Secure <9.1R5 on the PSAL Page.

CVE-2020-12880 ivanti vulnerability CVSS: 2.1 27 Jul 2020, 23:15 UTC

An issue was discovered in Pulse Policy Secure (PPS) and Pulse Connect Secure (PCS) Virtual Appliance before 9.1R8. By manipulating a certain kernel boot parameter, it can be tricked into dropping into a root shell in a pre-install phase where the entire source code of the appliance is available and can be retrieved. (The source code is otherwise inaccessible because the appliance has its hard disks encrypted, and no root shell is available during normal operation.)

CVE-2019-17066 ivanti vulnerability CVSS: 7.2 18 May 2020, 22:15 UTC

In Ivanti WorkSpace Control before 10.4.40.0, a user can elevate rights on the system by hijacking certain user registries. This is possible because pwrgrid.exe first checks the Current User registry hives (HKCU) when starting an application with elevated rights.

CVE-2020-12442 ivanti vulnerability CVSS: 7.5 28 Apr 2020, 22:15 UTC

Ivanti Avalanche 6.3 allows a SQL injection that is vaguely associated with the Apache HTTP Server, aka Bug 683250.

CVE-2020-11533 ivanti vulnerability CVSS: 2.1 04 Apr 2020, 20:15 UTC

Ivanti Workspace Control before 10.4.30.0, when SCCM integration is enabled, allows local users to obtain sensitive information (keying material).

CVE-2019-16382 ivanti vulnerability CVSS: 7.5 19 Mar 2020, 17:15 UTC

An issue was discovered in Ivanti Workspace Control 10.3.110.0. One is able to bypass Ivanti's FileGuard folder protection by renaming the WMTemp work folder used by PowerGrid. A malicious PowerGrid XML file can then be created, after which the folder is renamed back to its original value. Also, CVE-2018-15591 exploitation can consequently be achieved by using PowerGrid with the /SEE parameter to execute the arbitrary command specified in the XML file.

CVE-2019-19675 ivanti vulnerability CVSS: 4.4 17 Dec 2019, 15:15 UTC

In Ivanti Workspace Control before 10.3.180.0. a locally authenticated user with low privileges can bypass Managed Application Security by leveraging an unspecified attack vector in Workspace Preferences, when it is enabled. As a result, the attacker can start applications that should be blocked.

CVE-2019-10651 ivanti vulnerability CVSS: 7.5 11 Jul 2019, 18:15 UTC

An issue was discovered in the Core Server in Ivanti Endpoint Manager (EPM) 2017.3 before SU7 and 2018.x before 2018.3 SU3, with remote code execution. In other words, the issue affects 2017.3, 2018.1, and 2018.3 installations that lack the April 2019 update.

CVE-2018-20814 ivanti vulnerability CVSS: 4.3 28 Jun 2019, 18:15 UTC

An XSS issue was found with Psaldownload.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.3R2 before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before 5.4R2. This is not applicable to PCS 8.1RX or PPS 5.2RX.

CVE-2018-20813 ivanti vulnerability CVSS: 7.5 28 Jun 2019, 18:15 UTC

An input validation issue has been found with login_meeting.cgi in Pulse Secure Pulse Connect Secure 8.3RX before 8.3R2.

CVE-2018-20811 ivanti vulnerability CVSS: 5.0 28 Jun 2019, 18:15 UTC

A hidden RPC service issue was found with Pulse Secure Pulse Connect Secure 8.3RX before 8.3R2 and 8.1RX before 8.1R12.

CVE-2018-20810 ivanti vulnerability CVSS: 7.5 28 Jun 2019, 18:15 UTC

Session data between cluster nodes during cluster synchronization is not properly encrypted in Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before 5.4R2. This is not applicable to PCS 8.1RX, PPS 5.2RX, or stand-alone devices.

CVE-2018-20809 ivanti vulnerability CVSS: 5.0 28 Jun 2019, 18:15 UTC

A crafted message can cause the web server to crash with Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R5 and Pulse Policy Secure 5.4RX before 5.4R5. This is not applicable to PCS 8.1RX.

CVE-2018-20808 ivanti vulnerability CVSS: 4.3 28 Jun 2019, 18:15 UTC

An XSS issue has been found with rd.cgi in Pulse Secure Pulse Connect Secure 8.3RX before 8.3R3 due to improper header sanitization. This is not applicable to 8.1RX.

CVE-2018-20807 ivanti vulnerability CVSS: 4.3 28 Jun 2019, 18:15 UTC

An XSS issue has been found in welcome.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1.x before 8.1R12, 8.2.x before 8.2R9, and 8.3.x before 8.3R3 due to one of the URL parameters not being sanitized properly.

CVE-2019-11478 ivanti vulnerability CVSS: 5.0 19 Jun 2019, 00:15 UTC

Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit f070ef2ac66716357066b683fb0baf55f8191a2e.

CVE-2019-11477 ivanti vulnerability CVSS: 7.8 19 Jun 2019, 00:15 UTC

Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit 3b4929f65b0d8249f19a50245cd88ed1a2f78cff.

CVE-2019-12377 ivanti vulnerability CVSS: 7.5 03 Jun 2019, 20:29 UTC

A vulnerable upl/async_upload.asp web API endpoint in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 allows arbitrary file upload, which may lead to arbitrary remote code execution.

CVE-2019-12376 ivanti vulnerability CVSS: 2.7 03 Jun 2019, 20:29 UTC

Use of a hard-coded encryption key in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to full managed endpoint compromise by an authenticated user with read privileges.

CVE-2019-12375 ivanti vulnerability CVSS: 4.1 03 Jun 2019, 20:29 UTC

Open directories in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to remote information disclosure and arbitrary code execution.

CVE-2019-12374 ivanti vulnerability CVSS: 6.8 03 Jun 2019, 20:29 UTC

A SQL Injection vulnerability exists in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 due to improper username sanitization in the Basic Authentication implementation in core/provisioning.secure/ProvisioningSecure.asmx in Provisioning.Secure.dll.

CVE-2019-12373 ivanti vulnerability CVSS: 2.7 03 Jun 2019, 20:29 UTC

Improper access control and open directories in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to remote disclosure of administrator passwords.

CVE-2019-11509 ivanti vulnerability CVSS: 6.5 03 Jun 2019, 20:29 UTC

In Pulse Secure Pulse Connect Secure (PCS) before 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 and Pulse Policy Secure (PPS) before 5.1R15.1, 5.2 before 5.2R12.1, 5.3 before 5.3R15.1, 5.4 before 5.4R7.1, and 9.0 before 9.0R3.2, an authenticated attacker (via the admin web interface) can exploit Incorrect Access Control to execute arbitrary code on the appliance.

CVE-2019-11510 ivanti vulnerability CVSS: 7.5 08 May 2019, 17:29 UTC

In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .

CVE-2019-11508 ivanti vulnerability CVSS: 6.5 08 May 2019, 17:29 UTC

In Pulse Secure Pulse Connect Secure (PCS) before 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an authenticated attacker (via the admin web interface) can exploit Directory Traversal to execute arbitrary code on the appliance.

CVE-2019-11507 ivanti vulnerability CVSS: 4.3 08 May 2019, 17:29 UTC

In Pulse Secure Pulse Connect Secure (PCS) 8.3.x before 8.3R7.1 and 9.0.x before 9.0R3, an XSS issue has been found on the Application Launcher page.

CVE-2019-11543 ivanti vulnerability CVSS: 4.3 26 Apr 2019, 02:29 UTC

XSS exists in the admin web console in Pulse Secure Pulse Connect Secure (PCS) 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, and 5.2RX before 5.2R12.1.

CVE-2019-11542 ivanti vulnerability CVSS: 6.5 26 Apr 2019, 02:29 UTC

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, an authenticated attacker (via the admin web interface) can send a specially crafted message resulting in a stack buffer overflow.

CVE-2019-11541 ivanti vulnerability CVSS: 5.0 26 Apr 2019, 02:29 UTC

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.2RX before 8.2R12.1, users using SAML authentication with the Reuse Existing NC (Pulse) Session option may see authentication leaks.

CVE-2019-11540 ivanti vulnerability CVSS: 7.5 26 Apr 2019, 02:29 UTC

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4 and 8.3RX before 8.3R7.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2 and 5.4RX before 5.4R7.1, an unauthenticated, remote attacker can conduct a session hijacking attack.

CVE-2019-11539 ivanti vulnerability CVSS: 6.5 26 Apr 2019, 02:29 UTC

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, the admin web interface allows an authenticated attacker to inject and execute commands.

CVE-2019-11538 ivanti vulnerability CVSS: 4.0 26 Apr 2019, 02:29 UTC

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1, an NFS problem could allow an authenticated attacker to access the contents of arbitrary files on the affected device.

CVE-2019-11213 ivanti vulnerability CVSS: 6.8 12 Apr 2019, 15:29 UTC

In Pulse Secure Pulse Desktop Client and Network Connect, an attacker could access session tokens to replay and spoof sessions, and as a result, gain unauthorized access as an end user, a related issue to CVE-2019-1573. (The endpoint would need to be already compromised for exploitation to succeed.) This affects Pulse Desktop Client 5.x before Secure Desktop 5.3R7 and Pulse Desktop Client 9.x before Secure Desktop 9.0R3. It also affects (for Network Connect customers) Pulse Connect Secure 8.1 before 8.1R14, 8.3 before 8.3R7, and 9.0 before 9.0R3.

CVE-2019-10885 ivanti vulnerability CVSS: 4.6 05 Apr 2019, 17:29 UTC

An issue was discovered in Ivanti Workspace Control before 10.3.90.0. Local authenticated users with low privileges in a Workspace Control managed session can bypass Workspace Control security features configured for this session by resetting the session context.

CVE-2018-15593 ivanti vulnerability CVSS: 2.1 15 Oct 2018, 16:29 UTC

An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user can decrypt the encrypted datastore or relay server password by leveraging an unspecified attack vector.

CVE-2018-15592 ivanti vulnerability CVSS: 4.6 15 Oct 2018, 16:29 UTC

An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user can execute processes with elevated privileges via an unspecified attack vector.

CVE-2018-15591 ivanti vulnerability CVSS: 4.6 15 Oct 2018, 16:29 UTC

An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user can bypass Application Whitelisting restrictions to execute arbitrary code by leveraging multiple unspecified attack vectors.

CVE-2018-15590 ivanti vulnerability CVSS: 2.1 15 Oct 2018, 16:29 UTC

An issue was discovered in Ivanti Workspace Control before 10.3.0.0 and RES One Workspace, when file and folder security are configured. A local authenticated user can bypass file and folder security restriction by leveraging an unspecified attack vector.

CVE-2018-6320 ivanti vulnerability CVSS: 7.5 06 Sep 2018, 23:29 UTC

A vulnerability has been discovered in login.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1RX before 8.1R12 and 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.2RX before 5.2R9 and 5.4RX before 5.4R2 wherein an http(s) Host header received from the browser is trusted without validation.

CVE-2018-14366 ivanti vulnerability CVSS: 5.8 06 Sep 2018, 23:29 UTC

download.cgi in Pulse Secure Pulse Connect Secure 8.1RX before 8.1R13 and 8.3RX before 8.3R4 and Pulse Policy Secure through 5.2RX before 5.2R10 and 5.4RX before 5.4R4 have an Open Redirect Vulnerability.

CVE-2018-8902 ivanti vulnerability CVSS: 4.0 29 Jun 2018, 15:29 UTC

An issue was discovered in Ivanti Avalanche for all versions between 5.3 and 6.2. The impacted products used a single shared key encryption model to encrypt data. A user with access to system databases can use the discovered key to access potentially confidential stored data, which may include Wi-Fi passwords. This discovered key can be used for all instances of the product.

CVE-2018-8901 ivanti vulnerability CVSS: 2.1 29 Jun 2018, 15:29 UTC

An issue was discovered in Ivanti Avalanche for all versions between 5.3 and 6.2. A local user with database access privileges can read the encrypted passwords for users who authenticate via LDAP to Avalanche services. These passwords are stored in the Avalanche databases. This issue only affects customers who have enabled LDAP authentication in their configuration.

CVE-2018-6316 ivanti vulnerability CVSS: 6.0 15 Feb 2018, 23:29 UTC

Ivanti Endpoint Security (formerly HEAT Endpoint Management and Security Suite) 8.5 Update 1 and earlier allows an authenticated user with low privileges and access to the local network to bypass application whitelisting when using the Application Control module on Ivanti Endpoint Security in lockdown mode.

CVE-2017-11463 ivanti vulnerability CVSS: 6.5 11 Dec 2017, 06:29 UTC

In Ivanti Service Desk (formerly LANDESK Management Suite) versions between 2016.3 and 2017.3, an Unrestricted Direct Object Reference leads to referencing/updating objects belonging to other users. In other words, a normal user can send requests to a specific URI with the target user's username in an HTTP payload in order to retrieve a key/token and use it to access/update objects belonging to other users. Such objects could be user profiles, tickets, incidents, etc.

CVE-2017-11455 ivanti vulnerability CVSS: 6.8 29 Aug 2017, 15:29 UTC

diag.cgi in Pulse Connect Secure 8.2R1 through 8.2R5, 8.1R1 through 8.1R10 and Pulse Policy Secure 5.3R1 through 5.3R5, 5.2R1 through 5.2R8, and 5.1R1 through 5.1R10 allow remote attackers to hijack the authentication of administrators for requests to start tcpdump, related to the lack of anti-CSRF tokens.

CVE-2016-3147 ivanti vulnerability CVSS: 7.5 23 Jan 2017, 21:59 UTC

Buffer overflow in the collector.exe listener of the Landesk Management Suite 10.0.0.271 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large packet.

CVE-2016-4792 ivanti vulnerability CVSS: 5.0 26 May 2016, 14:59 UTC

Pulse Connect Secure (PCS) 8.2 before 8.2r1 allows remote attackers to disclose sign in pages via unspecified vectors.

CVE-2016-4791 ivanti vulnerability CVSS: 6.4 26 May 2016, 14:59 UTC

The administrative user interface in Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r9, and 7.4 before 7.4r13.4 allows remote administrators to enumerate files, read arbitrary files, and conduct server side request forgery (SSRF) attacks via unspecified vectors.

CVE-2016-4790 ivanti vulnerability CVSS: 3.5 26 May 2016, 14:59 UTC

Cross-site scripting (XSS) vulnerability in the administrative user interface in Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r9, and 7.4 before 7.4r13.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2016-4789 ivanti vulnerability CVSS: 4.3 26 May 2016, 14:59 UTC

Cross-site scripting (XSS) vulnerability in the system configuration section in the administrative user interface in Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r9, and 7.4 before 7.4r13.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2016-4788 ivanti vulnerability CVSS: 5.0 26 May 2016, 14:59 UTC

Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r10, and 7.4 before 7.4r13.4 allow remote attackers to read an unspecified system file via unknown vectors.

CVE-2016-4787 ivanti vulnerability CVSS: 6.4 26 May 2016, 14:59 UTC

Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r10, and 7.4 before 7.4r13.4 allow remote attackers to read sensitive system authentication files in an unspecified directory via unknown vectors.

CVE-2016-4786 ivanti vulnerability CVSS: 7.8 26 May 2016, 14:59 UTC

Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r3, 8.0 before 8.0r11, and 7.4 before 7.4r13.4 allow remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.