Multiple Vulnerabilities in Ivanti Products Could Allow for Remote Code Execution
ID: e700f34f-689d-5272-b6d2-33280a5f0518
STIX ID: report--e700f34f-689d-5272-b6d2-33280a5f0518
Feed Name: CISecurity.org Advisories
Multiple vulnerabilities were disclosed in Ivanti products: the most severe is a remote code execution issue in Ivanti Avalanche 6.3.1 (CVE-2024-37373). Additional reported issues include admin authentication bypass (CVE-2024-7593), information disclosure of OIDC client secrets (CVE-2024-7569), improper certificate validation enabling token forgery (CVE-2024-7570), several denial-of-service flaws, an XXE allowing file read (CVE-2024-38653), and a path traversal leading to arbitrary file deletion (CVE-2024-38652); successful exploitation could permit code execution, data access or deletion, and takeover depending on privileges.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
