CVE-2024-38648
MEDIUMIvanti DSM <2024.2 - Info Disclosure
Title source: llmDescription
A hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent network to decrypt sensitive data including user credentials.
Scores
CVSS v3
5.7
EPSS
0.0004
EPSS Percentile
11.3%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-798
Status
published
Affected Products (1)
ivanti/desktop_\&_server_management
< 2024.2
Timeline
Published
Jul 12, 2025
Tracked Since
Feb 18, 2026