Vulnerabilities > Ivanti > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-11-13 CVE-2024-29211 Race Condition vulnerability in Ivanti Secure Access Client
A race condition in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to modify sensitive configuration files.
local
high complexity
ivanti CWE-362
4.7
2024-11-12 CVE-2024-11004 Cross-site Scripting vulnerability in Ivanti Connect Secure 22.7/7.1/7.4
Reflected XSS in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote unauthenticated attacker to obtain admin privileges.
network
low complexity
ivanti CWE-79
6.1
2024-11-12 CVE-2024-9843 Out-of-bounds Read vulnerability in Ivanti Secure Access Client
A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denial of service.
local
low complexity
ivanti CWE-125
5.5
2024-11-12 CVE-2024-47905 Out-of-bounds Write vulnerability in Ivanti Connect Secure 22.7/7.1/7.4
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.
network
low complexity
ivanti CWE-787
4.9
2024-11-12 CVE-2024-47909 Out-of-bounds Write vulnerability in Ivanti Connect Secure 22.7/7.1/7.4
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.
network
low complexity
ivanti CWE-787
4.9
2024-09-10 CVE-2024-8320 Missing Authentication for Critical Function vulnerability in Ivanti Endpoint Manager
Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to spoof Network Isolation status of managed devices.
network
low complexity
ivanti CWE-306
5.3
2024-09-10 CVE-2024-8441 Uncontrolled Search Path Element vulnerability in Ivanti Endpoint Manager
An uncontrolled search path in the agent of Ivanti EPM before 2022 SU6, or the 2024 September update allows a local authenticated attacker with admin privileges to escalate their privileges to SYSTEM.
local
low complexity
ivanti CWE-427
6.7
2024-08-07 CVE-2024-34788 Improper Authentication vulnerability in Ivanti Endpoint Manager Mobile
An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to access potentially sensitive information
network
low complexity
ivanti CWE-287
6.5
2024-08-07 CVE-2024-37403 Path Traversal vulnerability in Ivanti Docs@Work
Ivanti Docs@Work for Android, before 2.26.0 is affected by the 'Dirty Stream' vulnerability.
local
low complexity
ivanti CWE-22
5.5
2024-05-22 CVE-2024-22026 Unspecified vulnerability in Ivanti Endpoint Manager Mobile
A local privilege escalation vulnerability in EPMM before 12.1.0.0 allows an authenticated local user to bypass shell restriction and execute arbitrary commands on the appliance.
local
low complexity
ivanti
6.7