Vulnerabilities in Ivanti

391 results
Vexday analysis

Com 24 vulnerabilidades confirmadas em exploração ativa dentro de um universo de 366 CVEs catalogadas, a taxa de presença no catálogo KEV da CISA é 14,6 vezes acima da média geral do catálogo, o que indica um histórico consistente de interesse de agentes de ameaça nos produtos Ivanti. Das 366 falhas, 83 são classificadas como críticas e 20 possuem prova de conceito pública disponível, aumentando a superfície de risco para organizações que não mantêm ciclos de correção agressivos. O tipo de falha mais recorrente é CWE-89 (injeção de SQL), sugerindo lacunas estruturais em validação de entradas que tendem a produzir vulnerabilidades de alto impacto. A CVE mais perigosa atualmente ativa, CVE-2024-21893, registra EPSS máximo de 1,0, indicando probabilidade extremamente elevada de exploração, e deve ser tratada como prioridade absoluta de remediação.

CVE-2024-13168HIGHAn out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote EPSS 2.6%CVE-2024-13167HIGHAn out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote EPSS 2.6%CVE-2024-27975HIGHAn Use-after-free vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to eEPSS 2.6%CVE-2023-32567MEDIUMIvanti Avalanche decodeToMap XML External Entity Processing. Fixed in version 6.4.1.236EPSS 2.5%CVE-2023-32561HIGHA previously generated artifact by an administrator could be accessed by an attacker. The contents of this artifact could lead to authenticaEPSS 2.4%CVE-2024-13166HIGHAn out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote EPSS 2.4%CVE-2024-23531HIGHAn Integer Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker EPSS 2.4%CVE-2023-39340HIGHA vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker can send a specific request which may lead toEPSS 2.4%CVE-2024-24993HIGHA Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute EPSS 2.4%CVE-2024-24995HIGHA Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute EPSS 2.4%CVE-2023-32566MEDIUMAn attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. FEPSS 2.4%CVE-2024-36131HIGHAn insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbiEPSS 2.3%CVE-2023-39335A security vulnerability has been identified in EPMM Versions 11.10, 11.9 and 11.8 and older allowing an unauthenticated threat actor to impEPSS 2.3%CVE-2024-36130CRITICALAn insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network toEPSS 2.3%CVE-2023-32565MEDIUMAn attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. FEPSS 2.2%CVE-2023-35077HIGHAn out-of-bounds write vulnerability on windows operating systems causes the Ivanti AntiVirus Product to crash. Update to Ivanti AV Product EPSS 2.2%CVE-2024-36136HIGHAn off-by-one error in WLInfoRailService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting EPSS 2.2%CVE-2026-12744CRITICALA Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execuEPSS 2.2%CVE-2024-32842CRITICALAn unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin pEPSS 2.1%CVE-2024-32846CRITICALAn unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin pEPSS 2.1%