Vulnerabilidades em Ivanti

391 resultados
Análise Vexday

Com 24 vulnerabilidades confirmadas em exploração ativa dentro de um universo de 366 CVEs catalogadas, a taxa de presença no catálogo KEV da CISA é 14,6 vezes acima da média geral do catálogo, o que indica um histórico consistente de interesse de agentes de ameaça nos produtos Ivanti. Das 366 falhas, 83 são classificadas como críticas e 20 possuem prova de conceito pública disponível, aumentando a superfície de risco para organizações que não mantêm ciclos de correção agressivos. O tipo de falha mais recorrente é CWE-89 (injeção de SQL), sugerindo lacunas estruturais em validação de entradas que tendem a produzir vulnerabilidades de alto impacto. A CVE mais perigosa atualmente ativa, CVE-2024-21893, registra EPSS máximo de 1,0, indicando probabilidade extremamente elevada de exploração, e deve ser tratada como prioridade absoluta de remediação.

CVE-2024-32839HIGHSQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticEPSS 3.4%CVE-2023-41719HIGHA vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker impersonating an administrator may craft a spEPSS 3.4%CVE-2021-3540MEDIUMIvanti MobileIron Core clish Restricted Shell Escape via Argument InjectionEPSS 3.3%CVE-2021-3198MEDIUMIvanti MobileIron Core clish Restricted Shell Escape via OS Command InjectionEPSS 3.3%CVE-2024-24997HIGHA Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitraryEPSS 3.2%CVE-2024-27976HIGHA Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitraryEPSS 3.2%CVE-2024-24998HIGHA Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitraryEPSS 3.2%CVE-2024-37376HIGHSQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticEPSS 3.2%CVE-2024-32847HIGHSQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticEPSS 3.2%CVE-2023-28323CRITICALA deserialization of untrusted data exists in EPM 2022 Su3 and all prior versions that allows an unauthenticated user to elevate rights. ThiEPSS 3.1%CVE-2024-37381HIGHAn unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2024 flat allows an authenticated attacker within the same network tEPSS 3.1%CVE-2024-25000HIGHA Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitraryEPSS 3.0%CVE-2024-22023MEDIUMAn XML entity expansion or XEE vulnerability in SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unautEPSS 3.0%CVE-2024-24999HIGHA Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitraryEPSS 2.9%CVE-2023-35084Unsafe Deserialization of User Input could lead to Execution of Unauthorized Operations in Ivanti Endpoint Manager 2022 su3 and all previousEPSS 2.8%CVE-2024-10644CRITICALCode injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticatEPSS 2.8%CVE-2024-23534HIGHAn Unrestricted File-upload vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to executEPSS 2.7%CVE-2024-13170HIGHAn out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote EPSS 2.7%CVE-2023-38036CRITICALA security vulnerability within Ivanti Avalanche Manager before version 6.4.1 may allow an unauthenticated attacker to create a buffer overfEPSS 2.7%CVE-2024-13165HIGHAn out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote EPSS 2.6%