Vulnerabilities > Ivanti > Connect Secure > Medium

DATE CVE VULNERABILITY TITLE RISK
2025-02-11 CVE-2024-13830 Cross-site Scripting vulnerability in Ivanti Connect Secure 22.7/7.1/7.4
Reflected XSS in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote unauthenticated attacker to obtain admin privileges.
network
low complexity
ivanti CWE-79
6.1
2025-02-11 CVE-2024-13842 Use of Hard-coded Cryptographic Key vulnerability in Ivanti Connect Secure 22.7/7.1/7.4
A hardcoded key in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.
local
low complexity
ivanti CWE-321
4.4
2025-02-11 CVE-2024-13843 Cleartext Storage of Sensitive Information vulnerability in Ivanti Connect Secure 22.7/7.1/7.4
Cleartext storage of information in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.
local
low complexity
ivanti CWE-312
4.4
2024-11-12 CVE-2024-11004 Cross-site Scripting vulnerability in Ivanti Connect Secure 22.7/7.1/7.4
Reflected XSS in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote unauthenticated attacker to obtain admin privileges.
network
low complexity
ivanti CWE-79
6.1
2024-11-12 CVE-2024-47905 Out-of-bounds Write vulnerability in Ivanti Connect Secure 22.7/7.1/7.4
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.
network
low complexity
ivanti CWE-787
4.9
2024-11-12 CVE-2024-47909 Out-of-bounds Write vulnerability in Ivanti Connect Secure 22.7/7.1/7.4
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.
network
low complexity
ivanti CWE-787
4.9
2024-04-04 CVE-2024-22023 NULL Pointer Dereference vulnerability in Ivanti Connect Secure and Policy Secure
An XML entity expansion or XEE vulnerability in SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated attacker to send specially crafted XML requests in-order-to temporarily cause resource exhaustion thereby resulting in a limited-time DoS.
network
low complexity
ivanti CWE-476
5.3
2022-09-30 CVE-2022-21826 HTTP Request Smuggling vulnerability in multiple products
Pulse Secure version 9.115 and below may be susceptible to client-side http request smuggling, When the application receives a POST request, it ignores the request's Content-Length header and leaves the POST body on the TCP/TLS socket.
network
low complexity
pulsesecure ivanti CWE-444
5.4
2021-08-16 CVE-2021-22933 Path Traversal vulnerability in multiple products
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform an arbitrary file delete via a maliciously crafted web request.
network
low complexity
pulsesecure ivanti CWE-22
6.5
2021-08-16 CVE-2021-22936 Cross-site Scripting vulnerability in multiple products
A vulnerability in Pulse Connect Secure before 9.1R12 could allow a threat actor to perform a cross-site script attack against an authenticated administrator via an unsanitized web parameter.
network
low complexity
pulsesecure ivanti CWE-79
6.1