PT-2024-6970 · Ivanti · Ivanti Velocity License Server

Published

2024-10-08

·

Updated

2024-11-04

·

CVE-2024-9167

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ivanti Velocity License Server versions prior to 5.2
Description The issue is related to insecure permissions in the Ivanti Velocity License Server, which can be exploited by a local authenticated attacker to achieve local privilege escalation. This is due to insufficient access control mechanisms.
Recommendations For versions prior to 5.2, update to version 5.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the Ivanti Velocity License Server to minimize the risk of exploitation.

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

BDU:2024-08219
CVE-2024-9167

Affected Products

Ivanti Velocity License Server