5.5

CVE-2023-38544

A logged in user can modify specific files that may lead to unauthorized changes in system-wide configuration settings. This vulnerability could be exploited to compromise the integrity and security of the network on the affected system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ivanti ≫ Secure Access Client Version 22.2 Update r1
   Linux ≫ Linux Kernel Version -
Ivanti ≫ Secure Access Client Version 22.3 Update r1
   Linux ≫ Linux Kernel Version -
Ivanti ≫ Secure Access Client Version 22.3 Update r2
   Linux ≫ Linux Kernel Version -
Ivanti ≫ Secure Access Client Version 22.3 Update r3
   Linux ≫ Linux Kernel Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.37% 0.29
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
HackerOne 5.3 1.8 3.4
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://forums.ivanti.com/s/article/Security-fixes-included-in-the-latest-Ivanti-Secure-Access-Client-Release
Vendor Advisory