PT-2024-39883 · Ivanti · Ivanti Automation

Published

2024-12-11

·

Updated

2024-12-16

·

CVE-2024-9845

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ivanti Automation versions prior to 2024.4.0.1
Description Under specific circumstances, insecure permissions in Ivanti Automation allow a local authenticated attacker to achieve local privilege escalation.
Recommendations For versions prior to 2024.4.0.1, update to version 2024.4.0.1 or later to resolve the issue.

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2024-9845

Affected Products

Ivanti Automation