A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine and, in some cases, resulting in a full compromise of the system.
References
Configurations
Configuration 1 (hide)
AND |
|
History
12 Aug 2024, 15:35
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-400 |
23 Nov 2023, 00:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Summary | A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine and, in some cases, resulting in a full compromise of the system. |
22 Nov 2023, 15:07
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:ivanti:secure_access_client:*:*:*:*:*:*:*:* cpe:2.3:a:ivanti:secure_access_client:22.6:r1:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
References | () https://forums.ivanti.com/s/article/Security-fixes-included-in-the-latest-Ivanti-Secure-Access-Client-Release - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
CWE | NVD-CWE-noinfo | |
First Time |
Microsoft windows
Microsoft Ivanti Ivanti secure Access Client |
15 Nov 2023, 00:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-11-15 00:15
Updated : 2024-08-12 15:35
NVD link : CVE-2023-38043
Mitre link : CVE-2023-38043
CVE.ORG link : CVE-2023-38043
JSON object : View
Products Affected
ivanti
- secure_access_client
microsoft
- windows
CWE