Vulnerabilities > Ivanti > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-03-10 | CVE-2022-44574 | Improper Authentication vulnerability in Ivanti Avalanche An improper authentication vulnerability exists in Avalanche version 6.3.x and below allows unauthenticated attacker to modify properties on specific port. | 7.5 |
2022-12-05 | CVE-2022-35254 | Resource Exhaustion vulnerability in Ivanti Connect Secure and Policy Secure An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions prior to 9.1R17 and 22.3R1, and Ivanti Neurons for Zero-Trust Access in versions prior to 22.3R1. | 7.5 |
2022-12-05 | CVE-2022-35258 | Incorrect Calculation vulnerability in Ivanti Connect Secure and Policy Secure An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions prior to 9.1R17 and 22.3R1, and Ivanti Neurons for Zero-Trust Access in versions prior to 22.3R1. | 7.5 |
2022-12-05 | CVE-2022-35259 | XML Injection (aka Blind XPath Injection) vulnerability in Ivanti Endpoint Manager XML Injection with Endpoint Manager 2022. | 7.8 |
2022-08-12 | CVE-2021-44720 | Use of Hard-coded Credentials vulnerability in multiple products In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is stored in the HTML source code of the "Maintenance > Push Configuration > Targets > Target Name" targets.cgi screen. | 7.2 |
2022-04-11 | CVE-2022-22572 | Unspecified vulnerability in Ivanti Incapptic Connect A non-admin user with user management permission can escalate his privilege to admin user via password reset functionality. | 8.8 |
2022-04-11 | CVE-2022-27088 | Unquoted Search Path or Element vulnerability in Ivanti DSM Remote Ivanti DSM Remote <= 6.3.1.1862 is vulnerable to an unquoted service path allowing local users to launch processes with elevated privileges. | 7.8 |
2022-04-06 | CVE-2021-30497 | Path Traversal vulnerability in Ivanti Avalanche 6.3.2 Ivanti Avalanche (Premise) 6.3.2 allows remote unauthenticated users to read arbitrary files via Absolute Path Traversal. | 7.5 |
2022-03-04 | CVE-2022-21828 | Unspecified vulnerability in Ivanti Incapptic Connect A user with high privilege access to the Incapptic Connect web console can remotely execute code on the Incapptic Connect server using a unspecified attack vector in Incapptic Connect version 1.40.0, 1.39.1, 1.39.0, 1.38.1, 1.38.0, 1.37.1, 1.37.0, 1.36.0, 1.35.5, 1.35.4 and 1.35.3. | 7.2 |
2021-12-15 | CVE-2019-19138 | Unspecified vulnerability in Ivanti Workspace Control Ivanti Workspace Control before 10.4.50.0 allows attackers to degrade integrity. | 7.5 |