logo

Multiple Vulnerabilities in Ivanti Products Could Allow for Remote Code Execution

ID: 736ae5f6-02a3-5405-a181-fd38a904cb91

STIX ID: report--736ae5f6-02a3-5405-a181-fd38a904cb91

Feed Name: CISecurity.org Advisories

Threat Score
75/100

Date Published: 2024-10-09

Date Updated: 2026-04-27

...
...

Multiple vulnerabilities have been disclosed in Ivanti products, including a critical remote code execution vulnerability (CVE-2024-37404) and numerous other issues such as SSRF, path traversal, SQL injection, command injection, NULL-pointer DoS, and local privilege escalation across Ivanti EPMM, Connect Secure, Avalanche, CSA, and Velocity License Server; successful exploitation could allow attackers to execute code, install programs, and access or modify data depending on system privileges.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.