Known Vulnerabilities
CVE-2024-29211
A race condition in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to modify sensitive configuration files.
HIGH
CVSS 7.1
Published Nov 13, 2024
CVE-2024-37398
Insufficient validation in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.
HIGH
CVSS 7.8
Published Nov 13, 2024
CVE-2024-7571
Incorrect permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.
HIGH
CVSS 7.8
Published Nov 12, 2024
CVE-2024-9843
A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denial of service.
MEDIUM
CVSS 5.0
Published Nov 12, 2024
CVE-2024-9842
Incorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to create arbitrary folders.
HIGH
CVSS 7.3
Published Nov 12, 2024