VYPR

DSM

by Ivanti

CVEs (4)

  • CVE-2024-29821HigOct 18, 2024
    risk 0.51cvss 7.8epss 0.00

    Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector.

  • CVE-2024-29213HigOct 18, 2024
    risk 0.51cvss 7.8epss 0.00

    Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector.

  • CVE-2023-28129HigAug 10, 2023
    risk 0.51cvss 7.8epss 0.00

    DSM 2022.2 SU2 and all prior versions allows a local low privileged account to execute arbitrary OS commands as the DSM software installation user.

  • CVE-2024-38648MedJul 12, 2025
    risk 0.37cvss 5.7epss 0.01

    A hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent network to decrypt sensitive data including user credentials.