7.8

CVE-2024-39709

Incorrect file permissions in Ivanti Connect Secure before version 22.6R2 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1 (Not Applicable to 9.1Rx) allow a local authenticated attacker to escalate their privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IvantiConnect Secure Version < 9.1
IvantiConnect Secure Version >= 21.9 < 22.6
IvantiConnect Secure Version9.1 Update-
IvantiConnect Secure Version22.6 Update-
IvantiConnect Secure Version22.6 Updater1
IvantiPolicy Secure Update- Version < 9.1
IvantiPolicy Secure Version >= 22.1 < 22.7
IvantiPolicy Secure Version9.1 Update-
IvantiPolicy Secure Version22.7 Update-
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.309
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
support@hackerone.com 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-732 Incorrect Permission Assignment for Critical Resource

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.