NA - CVE-2024-8320 - Missing authentication in Network Isolation of...
Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to spoof Network Isolation status of managed devices.
NA - CVE-2024-8321 - Missing authentication in Network Isolation of...
Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to isolate managed devices from the network.
NA - CVE-2024-8322 - Weak authentication in Patch Management of...
Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker to access restricted functionality.
NA - CVE-2024-8441 - An uncontrolled search path in the agent of...
An uncontrolled search path in the agent of Ivanti EPM before 2022 SU6, or the 2024 September update allows a local authenticated attacker with admin privileges to escalate their privileges to SYSTEM.
NA - CVE-2024-45597 - Pluto is a superset of Lua 5.4 with a focus on...
Pluto is a superset of Lua 5.4 with a focus on general-purpose programming. Scripts passing user-controlled values to http.request header values are affected. An attacker could use this to send...