Skip to main content

Ivanti Products Multiple Vulnerabilities

Release Date: 15 Nov 2024 4498 Views

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

TYPE: Networks OS

Multiple vulnerabilities have been identified in Ivanti Products. A remote attacker could exploit these vulnerability to trigger denial of service condition, remote code execution, elevation of privilege, data manipulation and sensitive information disclosure on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution
  • Information Disclosure
  • Elevation of Privilege
  • Data Manipulation

System / Technologies affected

  • Ivanti Avalanche versions 6.4.5 and prior
  • Ivanti Connect Secure (ICS) versions 22.7R2.2 and prior
  • Ivanti Policy Secure (IPS) versions 22.7R1.1 and prior
  • Ivanti Secure Access Client (ISAC) versions 22.7R3 and prior
  • Ivanti Endpoint Manager (EPM) 2022 SU6 September security update and prior
  • Ivanti Endpoint Manager (EPM) 2024 September security update and prior

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link