Ivanti

Endpoint Manager

112 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 76.47%
  • Veröffentlicht 01.07.2023 00:15:10
  • Zuletzt bearbeitet 21.11.2024 07:54:50

A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege escalation or remote code execution.

  • EPSS 6.88%
  • Veröffentlicht 05.12.2022 22:15:10
  • Zuletzt bearbeitet 24.04.2025 14:15:31

A privilege escalation vulnerability is identified in Ivanti EPM (LANDesk Management Suite) that allows a user to execute commands with elevated privileges.

  • EPSS 0.61%
  • Veröffentlicht 05.12.2022 22:15:10
  • Zuletzt bearbeitet 24.04.2025 14:15:32

XML Injection with Endpoint Manager 2022. 3 and below causing a download of a malicious file to run and possibly execute to gain unauthorized privileges.

  • EPSS 0.13%
  • Veröffentlicht 23.09.2022 14:15:12
  • Zuletzt bearbeitet 22.05.2025 21:15:22

The “LANDesk(R) Management Agent” service exposes a socket and once connected, it is possible to launch commands only for signed executables. This is a security bug that allows a limited user to get escalated admin privileges on their system.

Exploit
  • EPSS 5.84%
  • Veröffentlicht 16.11.2020 16:15:14
  • Zuletzt bearbeitet 21.11.2024 05:01:49

LDMS/alert_log.aspx in Ivanti Endpoint Manager through 2020.1 allows SQL Injection via a /remotecontrolauth/api/device request.

Exploit
  • EPSS 1.98%
  • Veröffentlicht 16.11.2020 16:15:14
  • Zuletzt bearbeitet 21.11.2024 05:01:49

In /ldclient/ldprov.cgi in Ivanti Endpoint Manager through 2020.1.1, an attacker is able to disclose information about the server operating system, local pathnames, and environment variables with no authentication required.

Exploit
  • EPSS 0.14%
  • Veröffentlicht 16.11.2020 16:15:14
  • Zuletzt bearbeitet 21.11.2024 05:01:49

Ivanti Endpoint Manager through 2020.1.1 allows XSS via /LDMS/frm_splitfrm.aspx, /LDMS/licensecheck.aspx, /LDMS/frm_splitcollapse.aspx, /LDMS/alert_log.aspx, /LDMS/ServerList.aspx, /LDMS/frm_coremainfrm.aspx, /LDMS/frm_findfrm.aspx, /LDMS/frm_taskfrm...

  • EPSS 5.17%
  • Veröffentlicht 12.11.2020 20:15:16
  • Zuletzt bearbeitet 21.11.2024 05:01:49

An unrestricted file-upload issue in EditLaunchPadDialog.aspx in Ivanti Endpoint Manager 2019.1 and 2020.1 allows an authenticated attacker to gain remote code execution by uploading a malicious aspx file. The issue is caused by insufficient file ext...

  • EPSS 0.11%
  • Veröffentlicht 12.11.2020 18:15:14
  • Zuletzt bearbeitet 21.11.2024 05:01:49

Several services are accessing named pipes in Ivanti Endpoint Manager through 2020.1.1 with default or overly permissive security attributes; as these services run as user ‘NT AUTHORITY\SYSTEM’, the issue can be used to escalate privileges from a loc...

  • EPSS 0.06%
  • Veröffentlicht 12.11.2020 18:15:14
  • Zuletzt bearbeitet 21.11.2024 05:01:49

Various components in Ivanti Endpoint Manager through 2020.1.1 rely on Windows search order when loading a (nonexistent) library file, allowing (under certain conditions) one to gain code execution (and elevation of privileges to the level of privile...