Vulnerabilidades en ivanti

391 resultados
Análisis Vexday

Ivanti apresenta 12 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando risco emergente e recente. Três são críticas (CVSS alto), mas nenhuma está sob exploração ativa confirmada no momento. A fraqueza dominante é CWE-732 (permissões incorretas), sugerindo problemas de controle de acesso que demandam priorização na correção.

CVE-2025-55148HIGHMissing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.EPSS 0.6%CVE-2025-55144MEDIUMMissing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.EPSS 0.6%CVE-2026-4914MEDIUMStored XSS in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker to obtain limited information from other user sessiEPSS 0.5%CVE-2024-13172HIGHImproper signature verification in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows EPSS 0.5%CVE-2022-43555HIGHIvanti Avalanche Printer Device Service Missing Authentication Local Privilege Escalation VulnerabilityEPSS 0.5%CVE-2022-43554HIGHIvanti Avalanche Smart Device Service Missing Authentication Local Privilege Escalation VulnerabilityEPSS 0.5%CVE-2024-37403MEDIUMIvanti Docs@Work for Android, before 2.26.0 is affected by the 'Dirty Stream' vulnerability. The application fails to properly sanitize fileEPSS 0.5%CVE-2023-41718HIGHWhen a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the affected system when haEPSS 0.5%CVE-2024-13169HIGHAn out-of-bounds read in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a local auEPSS 0.4%CVE-2025-8712MEDIUMMissing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 22EPSS 0.4%CVE-2025-0293MEDIUMCLRF injection in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticatEPSS 0.4%CVE-2025-22458HIGHDLL hijacking in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an authenticated attacker to escalate to EPSS 0.4%CVE-2026-3483HIGHAn exposed dangerous method in Ivanti DSM before version 2026.1.1 allows a local authenticated attacker to escalate their privileges.EPSS 0.4%CVE-2024-22058HIGHA buffer overflow allows a low privilege user on the local machine that has the EPM Agent installed to execute arbitrary code with elevated EPSS 0.4%CVE-2026-7432HIGHA race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEMEPSS 0.4%CVE-2025-5353HIGHA hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt stored SQL credentialEPSS 0.4%CVE-2025-22455HIGHA hardcoded key in Ivanti Workspace Control before version 10.19.0.0 allows a local authenticated attacker to decrypt stored SQL credentialsEPSS 0.4%CVE-2024-13164HIGHAn uninitialized resource in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a locaEPSS 0.4%CVE-2023-38544MEDIUMA logged in user can modify specific files that may lead to unauthorized changes in system-wide configuration settings. This vulnerability cEPSS 0.4%CVE-2026-8110HIGHIncorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenticated attacker to esEPSS 0.4%