Multiple Vulnerabilities in Ivanti Products Could Allow for Remote Code Execution
ID: 945e00cd-7d83-527d-b7cb-55a0ca512f63
STIX ID: report--945e00cd-7d83-527d-b7cb-55a0ca512f63
Feed Name: CISecurity.org Advisories
Multiple critical and high-severity vulnerabilities were disclosed in Ivanti products (notably EPM, Workspace Control, and Cloud Services Appliance), including unauthenticated remote code execution through SQL injection and insecure deserialization, OS command injection, XXE, authentication bypasses, DLL hijacking, privilege escalation, and other flaws across several CVEs. Successful exploitation could allow attackers to execute arbitrary code, escalate privileges, access or exfiltrate credentials and data, or isolate managed devices; affected organizations should prioritize vendor patches and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
