CVE Vulnerabilities

CVE-2024-9842

Privilege Defined With Unsafe Actions

Published: Nov 12, 2024 | Modified: Jan 17, 2025
CVSS 3.x
3.3
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Incorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to create arbitrary folders.

Weakness

A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.

Affected Software

Name Vendor Start Version End Version
Secure_access_client Ivanti * 22.7 (excluding)
Secure_access_client Ivanti 22.7 (including) 22.7 (including)
Secure_access_client Ivanti 22.7-r1 (including) 22.7-r1 (including)
Secure_access_client Ivanti 22.7-r1.1 (including) 22.7-r1.1 (including)
Secure_access_client Ivanti 22.7-r2 (including) 22.7-r2 (including)
Secure_access_client Ivanti 22.7-r3 (including) 22.7-r3 (including)

Potential Mitigations

References