CVE-2024-9842
12.11.2024, 17:15
Incorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to create arbitrary folders.Enginsight
Vendor | Product | Version |
---|---|---|
ivanti | secure_access_client | 𝑥 < 22.7 |
ivanti | secure_access_client | 22.7 |
ivanti | secure_access_client | 22.7:r1 |
ivanti | secure_access_client | 22.7:r1.1 |
ivanti | secure_access_client | 22.7:r2 |
ivanti | secure_access_client | 22.7:r3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-267 - Privilege Defined With Unsafe ActionsA particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.
- CWE-732 - Incorrect Permission Assignment for Critical ResourceThe product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.