Vulnerabilities > Ivanti > High

DATE CVE VULNERABILITY TITLE RISK
2023-03-10 CVE-2022-44574 Improper Authentication vulnerability in Ivanti Avalanche
An improper authentication vulnerability exists in Avalanche version 6.3.x and below allows unauthenticated attacker to modify properties on specific port.
network
low complexity
ivanti CWE-287
7.5
2022-12-05 CVE-2022-35254 Resource Exhaustion vulnerability in Ivanti Connect Secure and Policy Secure
An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions prior to 9.1R17 and 22.3R1, and Ivanti Neurons for Zero-Trust Access in versions prior to 22.3R1.
network
low complexity
ivanti CWE-400
7.5
2022-12-05 CVE-2022-35258 Incorrect Calculation vulnerability in Ivanti Connect Secure and Policy Secure
An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions prior to 9.1R17 and 22.3R1, and Ivanti Neurons for Zero-Trust Access in versions prior to 22.3R1.
network
low complexity
ivanti CWE-682
7.5
2022-12-05 CVE-2022-35259 XML Injection (aka Blind XPath Injection) vulnerability in Ivanti Endpoint Manager
XML Injection with Endpoint Manager 2022.
local
low complexity
ivanti CWE-91
7.8
2022-08-12 CVE-2021-44720 Use of Hard-coded Credentials vulnerability in multiple products
In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is stored in the HTML source code of the "Maintenance > Push Configuration > Targets > Target Name" targets.cgi screen.
network
low complexity
pulsesecure ivanti CWE-798
7.2
2022-04-11 CVE-2022-22572 Unspecified vulnerability in Ivanti Incapptic Connect
A non-admin user with user management permission can escalate his privilege to admin user via password reset functionality.
network
low complexity
ivanti
8.8
2022-04-11 CVE-2022-27088 Unquoted Search Path or Element vulnerability in Ivanti DSM Remote
Ivanti DSM Remote <= 6.3.1.1862 is vulnerable to an unquoted service path allowing local users to launch processes with elevated privileges.
local
low complexity
ivanti CWE-428
7.8
2022-04-06 CVE-2021-30497 Path Traversal vulnerability in Ivanti Avalanche 6.3.2
Ivanti Avalanche (Premise) 6.3.2 allows remote unauthenticated users to read arbitrary files via Absolute Path Traversal.
network
low complexity
ivanti CWE-22
7.5
2022-03-04 CVE-2022-21828 Unspecified vulnerability in Ivanti Incapptic Connect
A user with high privilege access to the Incapptic Connect web console can remotely execute code on the Incapptic Connect server using a unspecified attack vector in Incapptic Connect version 1.40.0, 1.39.1, 1.39.0, 1.38.1, 1.38.0, 1.37.1, 1.37.0, 1.36.0, 1.35.5, 1.35.4 and 1.35.3.
network
low complexity
ivanti
7.2
2021-12-15 CVE-2019-19138 Unspecified vulnerability in Ivanti Workspace Control
Ivanti Workspace Control before 10.4.50.0 allows attackers to degrade integrity.
network
low complexity
ivanti
7.5