VYPR

Vendor CVEs

Ivanti

All CVEs

515 total · sorted by risk
  • CVE-2024-8012HigSep 10, 2024
    risk 0.51cvss 7.8epss 0.00

    An authentication bypass weakness in the message broker service of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges.

  • CVE-2024-37399HigAug 14, 2024
    risk 0.51cvss 7.5epss 0.28

    A NULL pointer dereference in WLAvalancheService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS.

  • CVE-2024-22058HigMay 31, 2024
    risk 0.51cvss 7.8epss 0.00

    A buffer overflow allows a low privilege user on the local machine that has the EPM Agent installed to execute arbitrary code with elevated permissions in Ivanti EPM 2021.1 and older.

  • CVE-2023-38042HigMay 31, 2024
    risk 0.51cvss 7.8epss 0.00

    A local privilege escalation vulnerability in Ivanti Secure Access Client for Windows allows a low privileged user to execute code as SYSTEM.

  • CVE-2023-34298HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.01

    Pulse Secure Client SetupService Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Pulse Secure Client. An attacker must first obtain the ability to execute low-privileged…

  • CVE-2023-41720HigDec 14, 2023
    risk 0.51cvss 7.8epss 0.01

    A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker with a foothold on an Ivanti Connect Secure (ICS) appliance can escalate their privileges by exploiting a vulnerable installed application. This vulnerability allows the attacker to…

  • CVE-2023-41718HigNov 15, 2023
    risk 0.51cvss 7.8epss 0.00

    When a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the affected system when having control over a specific file.

  • CVE-2023-38543HigNov 15, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine.

  • CVE-2023-38043HigNov 15, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine and, in some cases,…

  • CVE-2023-35080HigNov 15, 2023
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to various security risks, including the escalation of privileges, denial of service, or…

  • CVE-2023-41726HigNov 3, 2023
    risk 0.51cvss 7.8epss 0.01

    Ivanti Avalanche Incorrect Default Permissions allows Local Privilege Escalation Vulnerability

  • CVE-2023-41725HigNov 3, 2023
    risk 0.51cvss 7.8epss 0.01

    Ivanti Avalanche EnterpriseServer Service Unrestricted File Upload Local Privilege Escalation Vulnerability

  • CVE-2022-44569HigNov 3, 2023
    risk 0.51cvss 7.8epss 0.01

    A locally authenticated attacker with low privileges can bypass authentication due to insecure inter-process communication.

  • CVE-2022-43555HigNov 3, 2023
    risk 0.51cvss 7.8epss 0.00

    Ivanti Avalanche Printer Device Service Missing Authentication Local Privilege Escalation Vulnerability

  • CVE-2022-43554HigNov 3, 2023
    risk 0.51cvss 7.8epss 0.00

    Ivanti Avalanche Smart Device Service Missing Authentication Local Privilege Escalation Vulnerability

  • CVE-2023-28129HigAug 10, 2023
    risk 0.51cvss 7.8epss 0.00

    DSM 2022.2 SU2 and all prior versions allows a local low privileged account to execute arbitrary OS commands as the DSM software installation user.

  • CVE-2022-35259HigDec 5, 2022
    risk 0.51cvss 7.8epss 0.01

    XML Injection with Endpoint Manager 2022. 3 and below causing a download of a malicious file to run and possibly execute to gain unauthorized privileges.

  • CVE-2022-27088HigApr 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Ivanti DSM Remote <= 6.3.1.1862 is vulnerable to an unquoted service path allowing local users to launch processes with elevated privileges.

  • CVE-2021-36235HigSep 1, 2021
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in Ivanti Workspace Control before 10.6.30.0. A locally authenticated user with low privileges can bypass File and Folder Security by leveraging an unspecified attack vector. As a result, the attacker can start applications with elevated privileges.

  • CVE-2020-13771HigNov 12, 2020
    risk 0.51cvss 7.8epss 0.01

    Various components in Ivanti Endpoint Manager through 2020.1.1 rely on Windows search order when loading a (nonexistent) library file, allowing (under certain conditions) one to gain code execution (and elevation of privileges to the level of privilege held by the vulnerable…

  • CVE-2020-13770HigNov 12, 2020
    risk 0.51cvss 7.8epss 0.00

    Several services are accessing named pipes in Ivanti Endpoint Manager through 2020.1.1 with default or overly permissive security attributes; as these services run as user ‘NT AUTHORITY\SYSTEM’, the issue can be used to escalate privileges from a local standard or service…

  • CVE-2019-17066HigMay 18, 2020
    risk 0.51cvss 7.8epss 0.00

    In Ivanti WorkSpace Control before 10.4.40.0, a user can elevate rights on the system by hijacking certain user registries. This is possible because pwrgrid.exe first checks the Current User registry hives (HKCU) when starting an application with elevated rights.

  • CVE-2019-19675HigDec 17, 2019
    risk 0.51cvss 7.8epss 0.00

    In Ivanti Workspace Control before 10.3.180.0. a locally authenticated user with low privileges can bypass Managed Application Security by leveraging an unspecified attack vector in Workspace Preferences, when it is enabled. As a result, the attacker can start applications that…

  • CVE-2019-11538HigApr 26, 2019
    risk 0.51cvss 7.7epss 0.07

    In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1, an NFS problem could allow an authenticated attacker to access the contents of arbitrary files on the affected device.

  • CVE-2019-10885HigApr 5, 2019
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in Ivanti Workspace Control before 10.3.90.0. Local authenticated users with low privileges in a Workspace Control managed session can bypass Workspace Control security features configured for this session by resetting the session context.

  • CVE-2018-15593HigOct 15, 2018
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user can decrypt the encrypted datastore or relay server password by leveraging an unspecified attack vector.

  • CVE-2018-15592HigOct 15, 2018
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user can execute processes with elevated privileges via an unspecified attack vector.

  • CVE-2018-15591HigOct 15, 2018
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user can bypass Application Whitelisting restrictions to execute arbitrary code by leveraging multiple unspecified attack vectors.

  • CVE-2018-8901HigJun 29, 2018
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in Ivanti Avalanche for all versions between 5.3 and 6.2. A local user with database access privileges can read the encrypted passwords for users who authenticate via LDAP to Avalanche services. These passwords are stored in the Avalanche databases. This…

  • CVE-2026-18127HigAug 11, 2026
    risk 0.50cvss 7.7epss 0.00

    External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage.

  • CVE-2026-14903HigJul 14, 2026
    risk 0.50cvss 7.7epss 0.01

    Path traversal in Ivanti  Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary files outside the web root.

  • CVE-2024-13181HigJan 14, 2025
    risk 0.50cvss 7.3epss 0.32

    Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication. This CVE addresses incomplete fixes from CVE-2024-47010.

  • CVE-2024-47010HigOct 8, 2024
    risk 0.50cvss 7.3epss 0.38

    Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.

  • CVE-2024-34783HigSep 12, 2024
    risk 0.50cvss 7.2epss 0.43

    An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-32848HigSep 12, 2024
    risk 0.50cvss 7.2epss 0.43

    An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2026-18125HigAug 11, 2026
    risk 0.49cvss 7.5epss 0.01

    An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker to crash an agent service.

  • CVE-2025-55148HigSep 9, 2025
    risk 0.49cvss 7.6epss 0.01

    Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with…

  • CVE-2025-5462HigAug 12, 2025
    risk 0.49cvss 7.5epss 0.01

    A heap-based buffer overflow in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote unauthenticated…

  • CVE-2025-5456HigAug 12, 2025
    risk 0.49cvss 7.5epss 0.01

    A buffer over-read vulnerability in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote unauthenticated…

  • CVE-2024-13170HigJan 14, 2025
    risk 0.49cvss 7.5epss 0.03

    An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.

  • CVE-2024-13168HigJan 14, 2025
    risk 0.49cvss 7.5epss 0.03

    An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.

  • CVE-2024-13167HigJan 14, 2025
    risk 0.49cvss 7.5epss 0.03

    An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.

  • CVE-2024-13166HigJan 14, 2025
    risk 0.49cvss 7.5epss 0.02

    An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.

  • CVE-2024-13165HigJan 14, 2025
    risk 0.49cvss 7.5epss 0.03

    An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.

  • CVE-2024-37401HigDec 12, 2024
    risk 0.49cvss 7.5epss 0.01

    An out-of-bounds read in IPsec of Ivanti Connect Secure before version 22.7R2.1 allows a remote unauthenticated attacker to cause a denial of service.

  • CVE-2024-37377HigDec 12, 2024
    risk 0.49cvss 7.5epss 0.02

    A heap-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to cause a denial of service.

  • CVE-2024-38649HigNov 13, 2024
    risk 0.49cvss 7.5epss 0.02

    An out-of-bounds write in IPsec of Ivanti Connect Secure before version 22.7R2.1(Not Applicable to 9.1Rx) allows a remote unauthenticated attacker to cause a denial of service.

  • CVE-2024-37400HigNov 13, 2024
    risk 0.49cvss 7.5epss 0.02

    An out of bounds read in Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to trigger an infinite loop, causing a denial of service.

  • CVE-2024-8495HigNov 12, 2024
    risk 0.49cvss 7.5epss 0.01

    A null pointer dereference in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote unauthenticated attacker to cause a denial of service.

  • CVE-2024-50331HigNov 12, 2024
    risk 0.49cvss 7.5epss 0.01

    An out-of-bounds read vulnerability in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to leak sensitive information in memory.

Page 6 of 11