9.1
CVE-2024-11772 -
Command injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
10
CVE-2024-11639 -
An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access
7.1
CVE-2024-7572 -
Insufficient permissions in Ivanti DSM before version 2024.3.5740 allows a local authenticated attacker to delete arbitrary files.
8.8
CVE-2024-8540 -
Insecure permissions in Ivanti Sentry before versions 9.20.2 and 10.0.2 or 10.1.0Β allow a local authenticated attacker to modify sensitive application components.
9.1
CVE-2024-11634 -
Command injection in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to achieve remote code execution. (Not applicable to 9.1Rx)
9.1
CVE-2024-11633 -
Argument injection in Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution
7.1
CVE-2024-9844 -
Insufficient server-side controls in Secure Application Manager of Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker to bypass restrictions.
7.1
CVE-2024-10256 -
Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.
7.2
CVE-2024-54008 - Authenticated Remote Code Execution (RCE) in HPE Aruba Networking AirWave Management Platform
An authenticated Remote Code Execution (RCE) vulnerability exists in the AirWave CLI. Successful exploitation of this vulnerability could allow a remote authenticated threat actor to run arbitrary commands as a privileged user on the underlying host.
5.7
CVE-2024-53244 - Risky command safeguards bypass in β/en-US/app/search/reportβ endpoint through βsβ parameter
In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.2.2406.107, 9.2.2403.109, and 9.1.2312.206, a low-privileged user that does not hold the βadminβ or βpowerβ Splunk roles could run a saved search with a risky command using the permissions of a hiβ¦