Vulnerabilities > Ivanti > High

DATE CVE VULNERABILITY TITLE RISK
2024-09-10 CVE-2024-8012 Missing Authentication for Critical Function vulnerability in Ivanti Workspace Control
An authentication bypass weakness in the message broker service of Ivanti Workspace Control version 10.18.0.0 and below allows a local authenticated attacker to escalate their privileges.
local
low complexity
ivanti CWE-306
7.8
2024-09-10 CVE-2024-8190 OS Command Injection vulnerability in Ivanti Cloud Services Appliance 4.6
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution.
network
low complexity
ivanti CWE-78
7.2
2024-09-10 CVE-2024-8321 Missing Authentication for Critical Function vulnerability in Ivanti Endpoint Manager
Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to isolate managed devices from the network.
network
low complexity
ivanti CWE-306
8.6
2024-09-10 CVE-2024-8322 Unspecified vulnerability in Ivanti Endpoint Manager
Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker to access restricted functionality.
network
low complexity
ivanti
8.8
2024-08-14 CVE-2024-36136 Off-by-one Error vulnerability in Ivanti Avalanche
An off-by-one error in WLInfoRailService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS.
network
low complexity
ivanti CWE-193
7.5
2024-08-14 CVE-2024-37373 Unspecified vulnerability in Ivanti Avalanche
Improper input validation in the Central Filestore in Ivanti Avalanche 6.3.1 allows a remote authenticated attacker with admin rights to achieve RCE.
network
low complexity
ivanti
7.2
2024-08-14 CVE-2024-37399 NULL Pointer Dereference vulnerability in Ivanti Avalanche
A NULL pointer dereference in WLAvalancheService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS.
network
low complexity
ivanti CWE-476
7.5
2024-08-14 CVE-2024-38653 XXE vulnerability in Ivanti Avalanche
XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.
network
low complexity
ivanti CWE-611
7.5
2024-08-13 CVE-2024-7570 Improper Certificate Validation vulnerability in Ivanti Neurons for Itsm 2023.2/2023.3/2023.4
Improper certificate validation in Ivanti ITSM on-prem and Neurons for ITSM Versions 2023.4 and earlier allows a remote attacker in a MITM position to craft a token that would allow access to ITSM as any user.
network
high complexity
ivanti CWE-295
8.1
2024-08-07 CVE-2024-36131 Deserialization of Untrusted Data vulnerability in Ivanti Endpoint Manager Mobile
An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary commands on the underlying operating system of the appliance.
network
low complexity
ivanti CWE-502
8.8