CVE-2023-28324
- EPSS 76.47%
- Veröffentlicht 01.07.2023 00:15:10
- Zuletzt bearbeitet 21.11.2024 07:54:50
A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege escalation or remote code execution.
CVE-2022-27773
- EPSS 6.88%
- Veröffentlicht 05.12.2022 22:15:10
- Zuletzt bearbeitet 24.04.2025 14:15:31
A privilege escalation vulnerability is identified in Ivanti EPM (LANDesk Management Suite) that allows a user to execute commands with elevated privileges.
CVE-2022-35259
- EPSS 0.61%
- Veröffentlicht 05.12.2022 22:15:10
- Zuletzt bearbeitet 24.04.2025 14:15:32
XML Injection with Endpoint Manager 2022. 3 and below causing a download of a malicious file to run and possibly execute to gain unauthorized privileges.
CVE-2022-30121
- EPSS 0.13%
- Veröffentlicht 23.09.2022 14:15:12
- Zuletzt bearbeitet 22.05.2025 21:15:22
The “LANDesk(R) Management Agent” service exposes a socket and once connected, it is possible to launch commands only for signed executables. This is a security bug that allows a limited user to get escalated admin privileges on their system.
CVE-2020-13769
- EPSS 5.84%
- Veröffentlicht 16.11.2020 16:15:14
- Zuletzt bearbeitet 21.11.2024 05:01:49
LDMS/alert_log.aspx in Ivanti Endpoint Manager through 2020.1 allows SQL Injection via a /remotecontrolauth/api/device request.
CVE-2020-13772
- EPSS 1.98%
- Veröffentlicht 16.11.2020 16:15:14
- Zuletzt bearbeitet 21.11.2024 05:01:49
In /ldclient/ldprov.cgi in Ivanti Endpoint Manager through 2020.1.1, an attacker is able to disclose information about the server operating system, local pathnames, and environment variables with no authentication required.
CVE-2020-13773
- EPSS 0.14%
- Veröffentlicht 16.11.2020 16:15:14
- Zuletzt bearbeitet 21.11.2024 05:01:49
Ivanti Endpoint Manager through 2020.1.1 allows XSS via /LDMS/frm_splitfrm.aspx, /LDMS/licensecheck.aspx, /LDMS/frm_splitcollapse.aspx, /LDMS/alert_log.aspx, /LDMS/ServerList.aspx, /LDMS/frm_coremainfrm.aspx, /LDMS/frm_findfrm.aspx, /LDMS/frm_taskfrm...
CVE-2020-13774
- EPSS 5.17%
- Veröffentlicht 12.11.2020 20:15:16
- Zuletzt bearbeitet 21.11.2024 05:01:49
An unrestricted file-upload issue in EditLaunchPadDialog.aspx in Ivanti Endpoint Manager 2019.1 and 2020.1 allows an authenticated attacker to gain remote code execution by uploading a malicious aspx file. The issue is caused by insufficient file ext...
CVE-2020-13770
- EPSS 0.11%
- Veröffentlicht 12.11.2020 18:15:14
- Zuletzt bearbeitet 21.11.2024 05:01:49
Several services are accessing named pipes in Ivanti Endpoint Manager through 2020.1.1 with default or overly permissive security attributes; as these services run as user ‘NT AUTHORITY\SYSTEM’, the issue can be used to escalate privileges from a loc...
CVE-2020-13771
- EPSS 0.06%
- Veröffentlicht 12.11.2020 18:15:14
- Zuletzt bearbeitet 21.11.2024 05:01:49
Various components in Ivanti Endpoint Manager through 2020.1.1 rely on Windows search order when loading a (nonexistent) library file, allowing (under certain conditions) one to gain code execution (and elevation of privileges to the level of privile...