Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ivanti endpoint manager vulnerabilities and exploits
(subscribe to this query)
801
VMScore
CVE-2020-13774
An unrestricted file-upload issue in EditLaunchPadDialog.aspx in Ivanti Endpoint Manager 2019.1 and 2020.1 allows an authenticated malicious user to gain remote code execution by uploading a malicious aspx file. The issue is caused by insufficient file extension validation and in...
Ivanti Endpoint Manager 2019.1
Ivanti Endpoint Manager 2020.1
668
VMScore
CVE-2021-44529
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
Ivanti Endpoint Manager Cloud Services Appliance
Ivanti Endpoint Manager Cloud Services Appliance 4.6
2 Github repositories
668
VMScore
CVE-2019-10651
An issue exists in the Core Server in Ivanti Endpoint Manager (EPM) 2017.3 before SU7 and 2018.x prior to 2018.3 SU3, with remote code execution. In other words, the issue affects 2017.3, 2018.1, and 2018.3 installations that lack the April 2019 update.
Ivanti Endpoint Manager 2018.3
Ivanti Endpoint Manager 2018.1
Ivanti Endpoint Manager 2017.3
668
VMScore
CVE-2019-12377
A vulnerable upl/async_upload.asp web API endpoint in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 allows arbitrary file upload, which may lead to arbitrary remote code execution.
Ivanti Landesk Management Suite 10.0.1.168
641
VMScore
CVE-2020-13770
Several services are accessing named pipes in Ivanti Endpoint Manager up to and including 2020.1.1 with default or overly permissive security attributes; as these services run as user ‘NT AUTHORITY\SYSTEM’, the issue can be used to escalate privileges from a local sta...
Ivanti Endpoint Manager
614
VMScore
CVE-2020-13771
Various components in Ivanti Endpoint Manager up to and including 2020.1.1 rely on Windows search order when loading a (nonexistent) library file, allowing (under certain conditions) one to gain code execution (and elevation of privileges to the level of privilege held by the vul...
Ivanti Endpoint Manager
605
VMScore
CVE-2019-12374
A SQL Injection vulnerability exists in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 due to improper username sanitization in the Basic Authentication implementation in core/provisioning.secure/ProvisioningSecure.asmx in Provisioning.Se...
Ivanti Landesk Management Suite 10.0.1.168
578
VMScore
CVE-2020-13769
LDMS/alert_log.aspx in Ivanti Endpoint Manager up to and including 2020.1 allows SQL Injection via a /remotecontrolauth/api/device request.
Ivanti Endpoint Manager
578
VMScore
CVE-2017-11463
In Ivanti Service Desk (formerly LANDESK Management Suite) versions between 2016.3 and 2017.3, an Unrestricted Direct Object Reference leads to referencing/updating objects belonging to other users. In other words, a normal user can send requests to a specific URI with the target...
Ivanti Endpoint Manager 2017.3
Ivanti Endpoint Manager 2016.4
Ivanti Endpoint Manager 2017.1
445
VMScore
CVE-2020-13772
In /ldclient/ldprov.cgi in Ivanti Endpoint Manager up to and including 2020.1.1, an attacker is able to disclose information about the server operating system, local pathnames, and environment variables with no authentication required.
Ivanti Endpoint Manager
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-29895
blind SQL injection
CVE-2024-5064
CVE-2023-52677
CVE-2023-52682
CVE-2024-30051
CVE-2024-35849
remote attackers
remote
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »