CVE-2024-37398
HIGHDescription
Insufficient validation in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.
Is your site exposed to CVE-2024-37398?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| ivanti | secure_access_client |
| ivanti | secure_access_client |
| ivanti | secure_access_client |
| ivanti | secure_access_client |
| ivanti | secure_access_client |
References
Frequently Asked Questions
What is CVE-2024-37398? +
How severe is CVE-2024-37398? +
What products are affected by CVE-2024-37398? +
How do I check if I'm vulnerable to CVE-2024-37398? +
Related Vulnerabilities
An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain …
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user …
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authenticated attacker to achieve remote code …
An file upload vulnerability in Ivanti ITSM before 2023.4, allows an authenticated remote user to perform file writes to the …
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a …
A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated …