Vulnerabilities in Ivanti

391 results
Vexday analysis

Com 24 vulnerabilidades confirmadas em exploração ativa dentro de um universo de 366 CVEs catalogadas, a taxa de presença no catálogo KEV da CISA é 14,6 vezes acima da média geral do catálogo, o que indica um histórico consistente de interesse de agentes de ameaça nos produtos Ivanti. Das 366 falhas, 83 são classificadas como críticas e 20 possuem prova de conceito pública disponível, aumentando a superfície de risco para organizações que não mantêm ciclos de correção agressivos. O tipo de falha mais recorrente é CWE-89 (injeção de SQL), sugerindo lacunas estruturais em validação de entradas que tendem a produzir vulnerabilidades de alto impacto. A CVE mais perigosa atualmente ativa, CVE-2024-21893, registra EPSS máximo de 1,0, indicando probabilidade extremamente elevada de exploração, e deve ser tratada como prioridade absoluta de remediação.

CVE-2024-11005CRITICALCommand injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.EPSS 1.6%CVE-2024-11007CRITICALCommand injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.EPSS 1.6%CVE-2024-11006CRITICALCommand injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.EPSS 1.6%CVE-2024-38657CRITICALExternal control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a rEPSS 1.6%CVE-2024-29205HIGHAn Improper Check for Unusual or Exceptional Conditions vulnerability in the web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti PEPSS 1.6%CVE-2024-37373HIGHImproper input validation in the Central Filestore in Ivanti Avalanche 6.3.1 allows a remote authenticated attacker with admin rights to achEPSS 1.6%CVE-2024-47907HIGHA stack-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to cause a EPSS 1.6%CVE-2024-37401HIGHAn out-of-bounds read in IPsec of Ivanti Connect Secure before version 22.7R2.1 allows a remote unauthenticated attacker to cause a denial oEPSS 1.5%CVE-2026-12651HIGHA Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to executeEPSS 1.5%CVE-2026-12648HIGHA Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to executeEPSS 1.5%CVE-2026-12650CRITICALA Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to executeEPSS 1.5%CVE-2026-83527HIGHAn Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated attacker to gain adminiEPSS 1.5%CVE-2026-9614HIGHAn Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authenticated attacker to gain aEPSS 1.4%CVE-2024-9420HIGHA use-after-free in Ivanti Connect Secure before version 22.7R2.3 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.2 allows a rEPSS 1.4%CVE-2024-8495HIGHA null pointer dereference in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remoteEPSS 1.4%CVE-2024-23533MEDIUMAn out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an autEPSS 1.4%CVE-2025-13661HIGHPath traversal in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote authenticated attacker to write arbitrary files outsEPSS 1.4%CVE-2025-22461HIGHSQL injection in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote authenticated attacker with admiEPSS 1.3%CVE-2024-36132HIGHInsufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authentication and access EPSS 1.2%CVE-2026-12645CRITICALA Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary cEPSS 1.2%