DSM
by Ivanti
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-29821 | Hig | 0.51 | 7.8 | 0.00 | Oct 18, 2024 | Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector. | ||
| CVE-2024-29213 | Hig | 0.51 | 7.8 | 0.00 | Oct 18, 2024 | Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector. | ||
| CVE-2023-28129 | Hig | 0.51 | 7.8 | 0.00 | Aug 10, 2023 | DSM 2022.2 SU2 and all prior versions allows a local low privileged account to execute arbitrary OS commands as the DSM software installation user. | ||
| CVE-2024-38648 | Med | 0.37 | 5.7 | 0.01 | Jul 12, 2025 | A hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent network to decrypt sensitive data including user credentials. |
- risk 0.51cvss 7.8epss 0.00
Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector.
- risk 0.51cvss 7.8epss 0.00
Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector.
- risk 0.51cvss 7.8epss 0.00
DSM 2022.2 SU2 and all prior versions allows a local low privileged account to execute arbitrary OS commands as the DSM software installation user.
- risk 0.37cvss 5.7epss 0.01
A hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent network to decrypt sensitive data including user credentials.