VYPR

Desktop\&server Management

by Ivanti

CVEs (7)

  • CVE-2020-12441CriAug 6, 2020
    risk 0.64cvss 9.8epss 0.04

    Denial-of-Service (DoS) in Ivanti Service Manager HEAT Remote Control 7.4 due to a buffer overflow in the protocol parser of the ‘HEATRemoteService’ agent. The DoS can be triggered by sending a specially crafted network packet.

  • CVE-2026-3483HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    An exposed dangerous method in Ivanti DSM before version 2026.1.1 allows a local authenticated attacker to escalate their privileges.

  • CVE-2024-29821HigOct 18, 2024
    risk 0.51cvss 7.8epss 0.00

    Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector.

  • CVE-2024-29213HigOct 18, 2024
    risk 0.51cvss 7.8epss 0.00

    Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector.

  • CVE-2023-28129HigAug 10, 2023
    risk 0.51cvss 7.8epss 0.00

    DSM 2022.2 SU2 and all prior versions allows a local low privileged account to execute arbitrary OS commands as the DSM software installation user.

  • CVE-2024-7572HigDec 10, 2024
    risk 0.46cvss 7.1epss 0.00

    Insufficient permissions in Ivanti DSM before version 2024.3.5740 allows a local authenticated attacker to delete arbitrary files.

  • CVE-2024-38648MedJul 12, 2025
    risk 0.37cvss 5.7epss 0.01

    A hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent network to decrypt sensitive data including user credentials.