VendorsIvantilandesk_management_suiteall versions
Vulnerabilities

Ivanti Landesk Management Suite

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2016-3147
Buffer overflow in the collector.exe listener of the Landesk Management Suite 10.0.0.271 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large packet.
Published 2017-01-23 · Modified
9.8EPSS 0.057
CVE-2019-12377
A vulnerable upl/async_upload.asp web API endpoint in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 allows arbitrary file upload, which may lead to arbitrary remote code execution.
Published 2019-06-03 · Modified
9.8EPSS 0.055
CVE-2019-12373
Improper access control and open directories in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to remote disclosure of administrator passwords.
Published 2019-06-03 · Modified
9.0EPSS 0.010
CVE-2019-12374
A SQL Injection vulnerability exists in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 due to improper username sanitization in the Basic Authentication implementation in core/provisioning.secure/ProvisioningSecure.asmx in Provisioning.Secure.dll.
Published 2019-06-03 · Modified
8.1EPSS 0.026
CVE-2019-12375
Open directories in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to remote information disclosure and arbitrary code execution.
Published 2019-06-03 · Modified
6.3EPSS 0.011
CVE-2019-12376
Use of a hard-coded encryption key in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to full managed endpoint compromise by an authenticated user with read privileges.
Published 2019-06-03 · Modified
4.5EPSS 0.006