Ivanti Vulnerabilities and Affected Products
Vulnerabilities associated with Workspace Control.
Products
Clear product- Avalanche94 vulnerabilities
- Endpoint Manager71 vulnerabilities
- Connect Secure62 vulnerabilities
- Policy Secure52 vulnerabilities
- endpoint_manager45 vulnerabilities
- EPM33 vulnerabilities
- connect_secure24 vulnerabilities
- policy_secure20 vulnerabilities
- Endpoint Manager Mobile18 vulnerabilities
- Secure Access Client15 vulnerabilities
- ZTA Gateway15 vulnerabilities
- Connect Secure and Policy Secure14 vulnerabilities
- Neurons for Secure Access13 vulnerabilities
- EPMM11 vulnerabilities
- Workspace Control10 vulnerabilities
- automation8 vulnerabilities
- endpoint_manager_mobile8 vulnerabilities
- Endpoint Manager Mobile (EPMM)7 vulnerabilities
- Pulse Connect Secure7 vulnerabilities
- CSA (Cloud Services Appliance)6 vulnerabilities
- endpoint_manager_cloud_services_appliance6 vulnerabilities
- secure_access_client6 vulnerabilities
- Sentry6 vulnerabilities
- Cloud Services Application5 vulnerabilities
- Endpoint Manager (EPM)5 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-5353HIGH | A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt stored SQL credentials. CWE-321Jun 10, 2025 | CVSS8.8v3.1 | EPSS0.35% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-22463HIGH | A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt the stored environment password. CWE-321Jun 10, 2025 | CVSS7.3v3.1 | EPSS0.335% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-22455HIGH | A hardcoded key in Ivanti Workspace Control before version 10.19.0.0 allows a local authenticated attacker to decrypt stored SQL credentials. CWE-321Jun 10, 2025 | CVSS8.8v3.1 | EPSS0.35% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-8496HIGH | Under specific circumstances, insecure permissions in Ivanti Workspace Control before version 10.18.40.0 allows a local authenticated attacker to achieve local privilege escalation. CWE-276Dec 11, 2024 | CVSS7.8v3.1 | EPSS0.21% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-44107HIGH | DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges and achieve arbitrary code execution. CWE-427Sep 10, 2024 | CVSS8.8v3.1 | EPSS0.266% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-44106HIGH | Insufficient server-side controls in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges. CWE-602Sep 10, 2024 | CVSS8.8v3.1 | EPSS0.245% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-44105HIGH | Cleartext transmission of sensitive information in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to obtain OS credentials. CWE-319Sep 10, 2024 | CVSS8.2v3.1 | EPSS0.163% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-44104HIGH | An incorrectly implemented authentication scheme that is subjected to a spoofing attack in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges. CWE-290Sep 10, 2024 | CVSS8.8v3.1 | EPSS0.237% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-44103HIGH | DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges. CWE-426Sep 10, 2024 | CVSS8.8v3.1 | EPSS0.245% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-8012HIGH | An authentication bypass weakness in the message broker service of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges. | CVSS7.8v3.1 | EPSS0.268% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |