CVE Vulnerabilities

CVE-2024-7571

Privilege Defined With Unsafe Actions

Published: Nov 12, 2024 | Modified: Jan 17, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Incorrect permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.

Weakness

A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.

Affected Software

NameVendorStart VersionEnd Version
Secure_access_clientIvanti*22.7 (excluding)
Secure_access_clientIvanti22.7 (including)22.7 (including)
Secure_access_clientIvanti22.7-r1 (including)22.7-r1 (including)
Secure_access_clientIvanti22.7-r1.1 (including)22.7-r1.1 (including)
Secure_access_clientIvanti22.7-r2 (including)22.7-r2 (including)
Secure_access_clientIvanti22.7-r3 (including)22.7-r3 (including)

Potential Mitigations

References