Ivanti

Landesk Management Suite

7 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.11%
  • Published 23.04.2025 00:00:00
  • Last modified 29.04.2025 13:52:47

A directory traversal vulnerability exists in Ivanti LANDesk Management Gateway through 4.2-1.9. By appending %3F.php to the URI of the /client/index.php endpoint, an attacker can bypass access controls and gain unauthorized access to various endpoin...

  • EPSS 0.24%
  • Published 03.06.2019 20:29:01
  • Last modified 21.11.2024 04:22:41

Open directories in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to remote information disclosure and arbitrary code execution.

Exploit
  • EPSS 0.03%
  • Published 03.06.2019 20:29:01
  • Last modified 21.11.2024 04:22:42

Use of a hard-coded encryption key in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to full managed endpoint compromise by an authenticated user with read privileges.

Exploit
  • EPSS 8.26%
  • Published 03.06.2019 20:29:01
  • Last modified 21.11.2024 04:22:42

A vulnerable upl/async_upload.asp web API endpoint in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 allows arbitrary file upload, which may lead to arbitrary remote code execution.

  • EPSS 0.06%
  • Published 03.06.2019 20:29:00
  • Last modified 21.11.2024 04:22:41

Improper access control and open directories in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to remote disclosure of administrator passwords.

Exploit
  • EPSS 0.66%
  • Published 03.06.2019 20:29:00
  • Last modified 21.11.2024 04:22:41

A SQL Injection vulnerability exists in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 due to improper username sanitization in the Basic Authentication implementation in core/provisioning.secure/Provisioning...

  • EPSS 6.07%
  • Published 23.01.2017 21:59:01
  • Last modified 20.04.2025 01:37:25

Buffer overflow in the collector.exe listener of the Landesk Management Suite 10.0.0.271 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large packet.