Vulnerabilidades en ivanti

391 resultados
Análisis Vexday

Ivanti apresenta 12 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando risco emergente e recente. Três são críticas (CVSS alto), mas nenhuma está sob exploração ativa confirmada no momento. A fraqueza dominante é CWE-732 (permissões incorretas), sugerindo problemas de controle de acesso que demandam priorização na correção.

CVE-2024-8012HIGHAn authentication bypass weakness in the message broker service of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a localEPSS 0.3%CVE-2024-44107HIGHDLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker EPSS 0.3%CVE-2024-7571HIGHIncorrect permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.EPSS 0.3%CVE-2025-5450MEDIUMImproper access control in the certificate management component of Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure beEPSS 0.3%CVE-2024-9843MEDIUMA buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denial of service.EPSS 0.3%CVE-2024-8540HIGHInsecure permissions in Ivanti Sentry before versions 9.20.2 and 10.0.2 or 10.1.0 allow a local authenticated attacker to modify sensitive aEPSS 0.3%CVE-2024-44103HIGHDLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker EPSS 0.2%CVE-2024-44106HIGHInsufficient server-side controls in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local autEPSS 0.2%CVE-2025-22464MEDIUMAn untrusted pointer dereference vulnerability in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an attacEPSS 0.2%CVE-2024-7612HIGHInsecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application components.EPSS 0.2%CVE-2025-10918HIGHInsecure default permissions in the agent of Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to write EPSS 0.2%CVE-2026-7431MEDIUMAn incorrect permission assignment for critical resource of Ivanti Secure Access Client   before 22.8R6 allows a local authenticated user toEPSS 0.2%CVE-2024-44104HIGHAn incorrectly implemented authentication scheme that is subjected to a spoofing attack in the management console of Ivanti Workspace ControEPSS 0.2%CVE-2024-9167HIGHUnder specific circumstances, insecure permissions in Ivanti Velocity License Server before version 5.2 allows a local authenticated attackeEPSS 0.2%CVE-2024-10630HIGHA race condition in Ivanti Application Control Engine before version 10.14.4.0 allows a local authenticated attacker to bypass the applicatiEPSS 0.2%CVE-2024-29821HIGHIvanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unsEPSS 0.2%CVE-2024-29213HIGHIvanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unsEPSS 0.2%CVE-2024-47906HIGHExcessive binary privileges in Ivanti Connect Secure before version 22.7R2.3 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before versiEPSS 0.2%CVE-2024-8539HIGHImproper authorization in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker to modify sensitive configEPSS 0.2%CVE-2024-13813HIGHInsufficient permissions in Ivanti Secure Access Client before version 22.8R1 allows a local authenticated attacker to delete arbitrary fileEPSS 0.2%