Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ivanti vulnerabilities and exploits
(subscribe to this query)
7.2
CVSSv3
CVE-2021-3198
By abusing the 'install rpm url' command, an attacker can escape the restricted clish shell on affected versions of Ivanti MobileIron Core. This issue was fixed in version 11.1.0.0.
Ivanti Mobileiron
8.8
CVSSv3
CVE-2021-42124
An improper access control vulnerability exists in Ivanti Avalanche prior to 6.3.3 allows an attacker with access to the Inforail Service to perform a session takeover.
Ivanti Avalanche
8.8
CVSSv3
CVE-2021-42126
An improper authorization control vulnerability exists in Ivanti Avalanche prior to 6.3.3 allows an attacker with access to the Inforail Service to perform privilege escalation.
Ivanti Avalanche
9.8
CVSSv3
CVE-2021-42127
A deserialization of untrusted data vulnerability exists in Ivanti Avalanche prior to 6.3.3 using Inforail Service allows arbitrary code execution via Data Repository Service.
Ivanti Avalanche
7.8
CVSSv3
CVE-2022-43554
Ivanti Avalanche Smart Device Service Missing Authentication Local Privilege Escalation Vulnerability
Ivanti Avalanche
7.8
CVSSv3
CVE-2022-43555
Ivanti Avalanche Printer Device Service Missing Authentication Local Privilege Escalation Vulnerability
Ivanti Avalanche
7.8
CVSSv3
CVE-2022-44569
A locally authenticated attacker with low privileges can bypass authentication due to insecure inter-process communication.
Ivanti Automation
1 Github repository
7.5
CVSSv3
CVE-2022-44574
An improper authentication vulnerability exists in Avalanche version 6.3.x and below allows unauthenticated malicious user to modify properties on specific port.
Ivanti Avalanche
9.8
CVSSv3
CVE-2022-36972
This vulnerability allows remote malicious users to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. The specific flaw exists within the ProfileDaoImpl class. A crafted request can trigger execution of SQL queries composed from a user-supplied strin...
Ivanti Avalanche
8.8
CVSSv3
CVE-2022-36973
This vulnerability allows remote malicious users to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists w...
Ivanti Avalanche
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-23316
SQL injection
type confusion
CVE-2024-20697
CVE-2024-4344
local
CVE-2024-30043
CVE-2024-3821
CVE-2024-5041
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
6
7
8
9
10
NEXT »