Ivanti Vulnerabilities and Affected Products
Vulnerabilities associated with ITSM.
Products
Clear product- Avalanche94 vulnerabilities
- Endpoint Manager71 vulnerabilities
- Connect Secure62 vulnerabilities
- Policy Secure52 vulnerabilities
- endpoint_manager45 vulnerabilities
- EPM33 vulnerabilities
- connect_secure24 vulnerabilities
- policy_secure20 vulnerabilities
- Endpoint Manager Mobile18 vulnerabilities
- Secure Access Client15 vulnerabilities
- ZTA Gateway15 vulnerabilities
- Connect Secure and Policy Secure14 vulnerabilities
- Neurons for Secure Access13 vulnerabilities
- EPMM11 vulnerabilities
- Workspace Control10 vulnerabilities
- automation8 vulnerabilities
- endpoint_manager_mobile8 vulnerabilities
- Endpoint Manager Mobile (EPMM)7 vulnerabilities
- Pulse Connect Secure7 vulnerabilities
- CSA (Cloud Services Appliance)6 vulnerabilities
- endpoint_manager_cloud_services_appliance6 vulnerabilities
- secure_access_client6 vulnerabilities
- Sentry6 vulnerabilities
- Cloud Services Application5 vulnerabilities
- Endpoint Manager (EPM)5 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-7570HIGH | Improper certificate validation in Ivanti ITSM on-prem and Neurons for ITSM Versions 2023.4 and earlier allows a remote attacker in a MITM position to craft a token that would allow access to ITSM as any user. CWE-295Aug 13, 2024 | CVSS8.3v3.1 | EPSS0.575% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-7569CRITICAL | An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the OIDC client secret via debug information. | CVSS9.6v3.1 | EPSS1.74% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-22059HIGH | A SQL injection vulnerability in web component of Ivanti Neurons for ITSM allows a remote authenticated user to read/modify/delete information in the underlying database. This may also lead to DoS. CWE-89May 31, 2024 | CVSS8.8v3.0 | EPSS1.07% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-22060MEDIUM | An unrestricted file upload vulnerability in web component of Ivanti Neurons for ITSM allows a remote, authenticated, high privileged user to write arbitrary files into sensitive directories of ITSM server. CWE-434May 31, 2024 | CVSS4.9v3.1 | EPSS1.12% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-46808CRITICAL | Ivanti neurons_for_itsm Unrestricted Upload of File with Dangerous TypeAn file upload vulnerability in Ivanti ITSM before 2023.4, allows an authenticated remote user to perform file writes to the server. Successful exploitation may lead to execution of commands in the context of non-root user. CWE-434Mar 31, 2024 | CVSS9.9v3.1 | EPSS2% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |