Vulnerabilities > Ivanti > Endpoint Manager > 2021.1.1
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-07-01 | CVE-2023-28323 | Deserialization of Untrusted Data vulnerability in Ivanti Endpoint Manager A deserialization of untrusted data exists in EPM 2022 Su3 and all prior versions that allows an unauthenticated user to elevate rights. | 9.8 |
2023-07-01 | CVE-2023-28324 | Improper Input Validation vulnerability in Ivanti Endpoint Manager A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege escalation or remote code execution. | 9.8 |
2022-12-05 | CVE-2022-35259 | XML Injection (aka Blind XPath Injection) vulnerability in Ivanti Endpoint Manager XML Injection with Endpoint Manager 2022. | 7.8 |
2022-09-23 | CVE-2022-30121 | Unspecified vulnerability in Ivanti Endpoint Manager The “LANDesk(R) Management Agent” service exposes a socket and once connected, it is possible to launch commands only for signed executables. | 6.7 |