CVE Vulnerabilities

CVE-2024-8539

Privilege Defined With Unsafe Actions

Published: Nov 12, 2024 | Modified: Jan 17, 2025
CVSS 3.x
7.1
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Improper authorization in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker to modify sensitive configuration files.

Weakness

A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.

Affected Software

NameVendorStart VersionEnd Version
Secure_access_clientIvanti*22.7 (excluding)
Secure_access_clientIvanti22.7 (including)22.7 (including)
Secure_access_clientIvanti22.7-r1 (including)22.7-r1 (including)
Secure_access_clientIvanti22.7-r1.1 (including)22.7-r1.1 (including)
Secure_access_clientIvanti22.7-r2 (including)22.7-r2 (including)

Potential Mitigations

References