PT-2024-6662 · Ivanti · Ivanti Workspace Control
Published
2024-09-10
·
Updated
2025-06-12
·
CVE-2024-44105
CVSS v3.1
8.2
High
| Vector | AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Ivanti Workspace Control versions 10.18.0.0 and below
Description:
The issue is related to the transmission of sensitive information in cleartext, allowing a local authenticated attacker to obtain operating system credentials. This can be exploited to gain unauthorized access to the system.
Recommendations:
For Ivanti Workspace Control versions 10.18.0.0 and below, update to a version above 10.18.0.0 to resolve the issue. As a temporary workaround, consider restricting access to the management console to minimize the risk of exploitation.
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ivanti Workspace Control