Ivanti

Policy Secure

78 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Published 08.07.2025 15:15:31
  • Last modified 15.07.2025 13:23:45

Improper access control in the certificate management component of Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated admin with read-only rights to modify settings that should...

Warning Media report
  • EPSS 71.7%
  • Published 03.04.2025 16:15:35
  • Last modified 03.05.2025 01:00:02

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.

  • EPSS 0.16%
  • Published 21.02.2025 02:15:28
  • Last modified 09.07.2025 14:50:48

External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to write arbitrary files.

  • EPSS 0.05%
  • Published 11.02.2025 16:15:39
  • Last modified 20.02.2025 15:55:03

Cleartext storage of information in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.

  • EPSS 0.09%
  • Published 11.02.2025 16:15:39
  • Last modified 20.02.2025 15:55:29

A hardcoded key in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.

  • EPSS 0.05%
  • Published 11.02.2025 16:15:39
  • Last modified 13.02.2025 17:09:11

Reflected XSS in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required.

  • EPSS 1.38%
  • Published 11.02.2025 16:15:38
  • Last modified 16.07.2025 16:00:23

External control of a file name in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to read arbitrary files.

  • EPSS 19.68%
  • Published 11.02.2025 16:15:38
  • Last modified 14.07.2025 13:11:26

Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • EPSS 0.09%
  • Published 08.01.2025 23:15:09
  • Last modified 14.01.2025 15:58:55

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a local authenticated attacker to escalate their privileg...

Warning Media report Exploit
  • EPSS 93.1%
  • Published 08.01.2025 23:15:09
  • Last modified 17.03.2025 19:24:45

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code ...