Ivanti / ICS
5 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-22024 | An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which… | HIGH | 8.3 | Feb 13, 2024 |
| CVE-2024-21893 KEV | A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons… | HIGH | 8.2 | Jan 31, 2024 |
| CVE-2024-21888 | A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elevate privil… | HIGH | 8.8 | Jan 31, 2024 |
| CVE-2024-21887 KEV | A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administr… | CRITICAL | 9.1 | Jan 12, 2024 |
| CVE-2023-46805 KEV | An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted reso… | HIGH | 8.2 | Jan 12, 2024 |
Showing 1 to 5 of 5 CVEs