VendorsIvantisecure_access_client22.7
Vulnerabilities

Ivanti Secure Access Client 22.7

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2024-37398
Insufficient validation in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.
Published 2024-11-13 · Analyzed
7.8EPSS 0.003
CVE-2025-22454
Insufficiently restrictive permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.
Published 2025-03-11 · Analyzed
7.8EPSS 0.003
CVE-2024-7571
Incorrect permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.
Published 2024-11-12 · Analyzed
7.8EPSS 0.003
CVE-2024-9842
Incorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to create arbitrary folders.
Published 2024-11-12 · Analyzed
7.3EPSS 0.002
CVE-2024-29211
A race condition in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to modify sensitive configuration files.
Published 2024-11-13 · Analyzed
7.1EPSS 0.003
CVE-2024-8539
Improper authorization in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker to modify sensitive configuration files.
Published 2024-11-12 · Analyzed
7.1EPSS 0.002
CVE-2024-9843
A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denial of service.
Published 2024-11-12 · Analyzed
5.5EPSS 0.003
CVE-2024-38654
Improper bounds checking in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker with admin privileges to cause a denial of service.
Published 2024-11-13 · Analyzed
4.4EPSS 0.003