« Volver al listado

CVE-2024-9842

Estado: AnalizadaBaja (3.3)—

Incorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to create arbitrary folders.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-9842",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-9842",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-11-12T18:24:43.136160Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "3c1d8aa1-5a33-4ea4-8992-aadd6440af75",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 7.3,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 4.7,
        "exploitabilityScore": 2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.3,
          "attackVector": "LOCAL",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "3c1d8aa1-5a33-4ea4-8992-aadd6440af75",
      "affectedData": [
        {
          "vendor": "Ivanti",
          "product": "Secure Access Client",
          "versions": [
            {
              "status": "unaffected",
              "version": "22.7R4",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2024-11-12T17:15:11.580",
  "references": [
    {
      "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "3c1d8aa1-5a33-4ea4-8992-aadd6440af75"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "3c1d8aa1-5a33-4ea4-8992-aadd6440af75",
      "description": [
        {
          "lang": "en",
          "value": "CWE-267"
        },
        {
          "lang": "en",
          "value": "CWE-732"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-732"
        },
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Incorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to create arbitrary folders."
    },
    {
      "lang": "es",
      "value": "Los permisos incorrectos en Ivanti Secure Access Client anteriores a la versión 22.7R4 permiten que un atacante autenticado local cree carpetas arbitrarias."
    }
  ],
  "lastModified": "2026-06-17T08:25:22.093",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ivanti:secure_access_client:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2347060E-FEC7-41EF-A0C0-5ED61B157223",
              "versionEndExcluding": "22.7"
            },
            {
              "criteria": "cpe:2.3:a:ivanti:secure_access_client:22.7:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C419EC4C-AB98-4D73-82B2-00A0A1F5A435"
            },
            {
              "criteria": "cpe:2.3:a:ivanti:secure_access_client:22.7:r1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F78C1CDE-FB11-4033-AEBA-D04D937EDD67"
            },
            {
              "criteria": "cpe:2.3:a:ivanti:secure_access_client:22.7:r1.1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "12DF0E17-F261-48D1-B2B8-50E9AEAFEC27"
            },
            {
              "criteria": "cpe:2.3:a:ivanti:secure_access_client:22.7:r2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E881D4BF-3222-4EF9-8A9B-0948973CCC89"
            },
            {
              "criteria": "cpe:2.3:a:ivanti:secure_access_client:22.7:r3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D93F7D15-B61D-4EE7-9280-FC0B7C45C940"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "3c1d8aa1-5a33-4ea4-8992-aadd6440af75"
}