Search: "ivanti"

379 CVEs found

CVE-2020-12441
9.8 CRITICAL

Denial-of-Service (DoS) in Ivanti Service Manager HEAT Remote Control 7.4 due to a buffer overflow in the protocol parser of the ‘HEATRemoteService’ agent. The DoS can be triggered by sending a specia...

Published: 2020-08-06
Products: 2
Vendors:
ivanti
CVE-2020-13793
9.8 CRITICAL

Unsafe storage of AD credentials in Ivanti DSM netinst 5.1 due to a static, hard-coded encryption key.

Published: 2020-08-06
Products: 1
Vendors:
ivanti

Several services are accessing named pipes in Ivanti Endpoint Manager through 2020.1.1 with default or overly permissive security attributes; as these services run as user ‘NT AUTHORITY\SYSTEM’, the i...

Published: 2020-11-12
Products: 1
Vendors:
ivanti

Various components in Ivanti Endpoint Manager through 2020.1.1 rely on Windows search order when loading a (nonexistent) library file, allowing (under certain conditions) one to gain code execution (a...

Published: 2020-11-12
Products: 1
Vendors:
ivanti
CVE-2020-13774
9.9 CRITICAL

An unrestricted file-upload issue in EditLaunchPadDialog.aspx in Ivanti Endpoint Manager 2019.1 and 2020.1 allows an authenticated attacker to gain remote code execution by uploading a malicious aspx ...

Published: 2020-11-12
Products: 2
Vendors:
ivanti

LDMS/alert_log.aspx in Ivanti Endpoint Manager through 2020.1 allows SQL Injection via a /remotecontrolauth/api/device request.

Published: 2020-11-16
Products: 1
Vendors:
ivanti
CVE-2020-13772
5.3 MEDIUM

In /ldclient/ldprov.cgi in Ivanti Endpoint Manager through 2020.1.1, an attacker is able to disclose information about the server operating system, local pathnames, and environment variables with no a...

Published: 2020-11-16
Products: 1
Vendors:
ivanti
CVE-2020-13773
5.4 MEDIUM

Ivanti Endpoint Manager through 2020.1.1 allows XSS via /LDMS/frm_splitfrm.aspx, /LDMS/licensecheck.aspx, /LDMS/frm_splitcollapse.aspx, /LDMS/alert_log.aspx, /LDMS/ServerList.aspx, /LDMS/frm_coremainf...

Published: 2020-11-16
Products: 1
Vendors:
ivanti
CVE-2021-3198
6.5 MEDIUM

By abusing the 'install rpm url' command, an attacker can escape the restricted clish shell on affected versions of Ivanti MobileIron Core. This issue was fixed in version 11.1.0.0.

Published: 2021-07-22
Products: 2
Vendors:
ivanti
CVE-2021-3540
6.5 MEDIUM

By abusing the 'install rpm info detail' command, an attacker can escape the restricted clish shell on affected versions of Ivanti MobileIron Core. This issue was fixed in version 11.1.0.0.

Published: 2021-07-22
Products: 2
Vendors:
ivanti

An issue was discovered in Ivanti Workspace Control before 10.6.30.0. A locally authenticated user with low privileges can bypass File and Folder Security by leveraging an unspecified attack vector. A...

Published: 2021-09-01
Products: 1
Vendors:
ivanti

An improper access control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform a session takeover.

Published: 2021-12-07
Products: 1
Vendors:
ivanti

An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to write dangerous files.

Published: 2021-12-07
Products: 1
Vendors:
ivanti

An improper authorization control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform privilege escalation.

Published: 2021-12-07
Products: 1
Vendors:
ivanti
CVE-2021-42127
9.8 CRITICAL

A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 using Inforail Service allows arbitrary code execution via Data Repository Service.

Published: 2021-12-07
Products: 1
Vendors:
ivanti
CVE-2021-42128
9.8 CRITICAL

An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 using inforail Service allows Privilege Escalation via Enterprise Server Service.

Published: 2021-12-07
Products: 1
Vendors:
ivanti

A command injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary command execution.

Published: 2021-12-07
Products: 1
Vendors:
ivanti

A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary code execution.

Published: 2021-12-07
Products: 1
Vendors:
ivanti

A SQL Injection vulnerability exists in Ivanti Avalance before 6.3.3 allows an attacker with access to the Inforail Service to perform privilege escalation.

Published: 2021-12-07
Products: 1
Vendors:
ivanti

A command Injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary command execution.

Published: 2021-12-07
Products: 1
Vendors:
ivanti