Ivanti
Ivanti Secure Access Client: vulnerabilidades y CVE
Ivanti Secure Access Client tiene 21 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE21
Últimos 12 meses3
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-8992 | Alta (8.8) | 1.2% | — | 22 may 2026 | An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code. |
| CVE-2026-7432 | Alta (7) | 0.38% | — | 12 may 2026 | A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM |
| CVE-2026-7431 | Media (4.4) | 0.24% | — | 12 may 2026 | An incorrect permission assignment for critical resource of Ivanti Secure Access Client before 22.8R6 allows a local authenticated user to read or modify sensitive log data via write access to a shared memory section. |
| CVE-2025-22454 | Alta (7.8) | 0.30% | — | 11 mar 2025 | Insufficiently restrictive permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges. |
| CVE-2024-13813 | Alta (7.1) | 0.21% | — | 11 feb 2025 | Insufficient permissions in Ivanti Secure Access Client before version 22.8R1 allows a local authenticated attacker to delete arbitrary files. |
| CVE-2024-38654 | Media (4.4) | 0.28% | — | 13 nov 2024 | Improper bounds checking in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker with admin privileges to cause a denial of service. |
| CVE-2024-37398 | Alta (7.8) | 0.32% | — | 13 nov 2024 | Insufficient validation in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges. |
| CVE-2024-29211 | Media (4.7) | 0.30% | — | 13 nov 2024 | A race condition in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to modify sensitive configuration files. |
| CVE-2024-9843 | Media (5.5) | 0.26% | — | 12 nov 2024 | A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denial of service. |
| CVE-2024-9842 | Baja (3.3) | 0.21% | — | 12 nov 2024 | Incorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to create arbitrary folders. |
| CVE-2024-8539 | Alta (7.1) | 0.22% | — | 12 nov 2024 | Improper authorization in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker to modify sensitive configuration files. |
| CVE-2024-7571 | Alta (7.8) | 0.26% | — | 12 nov 2024 | Incorrect permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges. |
| CVE-2023-46810 | Alta (7.3) | 0.31% | — | 31 may 2024 | A local privilege escalation vulnerability in Ivanti Secure Access Client for Linux before 22.7R1, allows a low privileged user to execute code as root. |
| CVE-2023-38042 | Alta (7.8) | 0.34% | — | 31 may 2024 | A local privilege escalation vulnerability in Ivanti Secure Access Client for Windows allows a low privileged user to execute code as SYSTEM. |
| CVE-2023-34298 | Alta (7.8) | 0.97% | — | 3 may 2024 | Pulse Secure Client SetupService Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Pulse Secure Client. An… |
| CVE-2023-41718 | Alta (7.8) | 0.45% | — | 15 nov 2023 | When a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the affected system when having control over a specific file. |
| CVE-2023-38544 | Media (5.5) | 0.37% | — | 15 nov 2023 | A logged in user can modify specific files that may lead to unauthorized changes in system-wide configuration settings. This vulnerability could be exploited to compromise the integrity and security of the network on… |
| CVE-2023-38543 | Alta (7.8) | 0.37% | — | 15 nov 2023 | A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of… |
| CVE-2023-38043 | Alta (7.8) | 0.37% | — | 15 nov 2023 | A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of… |
| CVE-2023-35080 | Alta (7.8) | 0.71% | — | 15 nov 2023 | A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to various security risks,… |
| CVE-2023-38041 | Alta (7) | 0.67% | — | 25 oct 2023 | A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flow is initiated, an attacker can exploit this condition to gain unauthorized… |