CVE Vulnerabilities

CVE-2024-8012

Authentication Bypass Using an Alternate Path or Channel

Published: Sep 10, 2024 | Modified: Jun 12, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An authentication bypass weakness in the message broker service of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges.

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

Name Vendor Start Version End Version
Workspace_control Ivanti * 10.18.99.0 (excluding)

Potential Mitigations

References