Medium severity5.7NVD Advisory· Published Jul 12, 2025· Updated Jun 17, 2026
CVE-2024-38648
CVE-2024-38648
Description
A hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent network to decrypt sensitive data including user credentials.
Affected products
2- Ivanti/DSMv5Range: 2024.2
Patches
Vulnerability mechanics
References
1- forums.ivanti.com/s/article/SA-2024-07-12-CVE-2024-38648nvdVendor Advisory
News mentions
0No linked articles in our index yet.