Vulnerabilities > Ivanti > Medium

DATE CVE VULNERABILITY TITLE RISK
2025-02-11 CVE-2024-13830 Cross-site Scripting vulnerability in Ivanti Connect Secure 22.7/7.1/7.4
Reflected XSS in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote unauthenticated attacker to obtain admin privileges.
network
low complexity
ivanti CWE-79
6.1
2025-02-11 CVE-2024-13842 Use of Hard-coded Cryptographic Key vulnerability in Ivanti Connect Secure 22.7/7.1/7.4
A hardcoded key in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.
local
low complexity
ivanti CWE-321
4.4
2025-02-11 CVE-2024-13843 Cleartext Storage of Sensitive Information vulnerability in Ivanti Connect Secure 22.7/7.1/7.4
Cleartext storage of information in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.
local
low complexity
ivanti CWE-312
4.4
2024-11-13 CVE-2024-29211 Race Condition vulnerability in Ivanti Secure Access Client
A race condition in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to modify sensitive configuration files.
local
high complexity
ivanti CWE-362
4.7
2024-11-12 CVE-2024-11004 Cross-site Scripting vulnerability in Ivanti Connect Secure 22.7/7.1/7.4
Reflected XSS in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote unauthenticated attacker to obtain admin privileges.
network
low complexity
ivanti CWE-79
6.1
2024-11-12 CVE-2024-9843 Out-of-bounds Read vulnerability in Ivanti Secure Access Client
A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denial of service.
local
low complexity
ivanti CWE-125
5.5
2024-11-12 CVE-2024-47905 Out-of-bounds Write vulnerability in Ivanti Connect Secure 22.7/7.1/7.4
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.
network
low complexity
ivanti CWE-787
4.9
2024-11-12 CVE-2024-47909 Out-of-bounds Write vulnerability in Ivanti Connect Secure 22.7/7.1/7.4
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.
network
low complexity
ivanti CWE-787
4.9
2024-09-10 CVE-2024-8320 Missing Authentication for Critical Function vulnerability in Ivanti Endpoint Manager
Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to spoof Network Isolation status of managed devices.
network
low complexity
ivanti CWE-306
5.3
2024-09-10 CVE-2024-8441 Uncontrolled Search Path Element vulnerability in Ivanti Endpoint Manager
An uncontrolled search path in the agent of Ivanti EPM before 2022 SU6, or the 2024 September update allows a local authenticated attacker with admin privileges to escalate their privileges to SYSTEM.
local
low complexity
ivanti CWE-427
6.7