« Back to list

Ivanti

Ivanti Automation: vulnerabilities and CVEs

Ivanti Automation has 2 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs2
Last 12 months0
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2024-9845High (7.8)0.21%—Dec 11, 2024
Under specific circumstances, insecure permissions in Ivanti Automation before version 2024.4.0.1 allows a local authenticated attacker to achieve local privilege escalation.
CVE-2022-44569High (7.8)0.76%—Nov 3, 2023
A locally authenticated attacker with low privileges can bypass authentication due to insecure inter-process communication.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1068 Exploitation for Privilege Escalation1
  2. T1222 File and Directory Permissions Modification1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Ivanti