PT-2025-29292 · Ivanti · Ivanti Dsm

Published

2025-07-12

·

Updated

2025-07-12

·

CVE-2024-38648

CVSS v3.1

9.0

Critical

VectorAV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Ivanti DSM versions prior to 2024.2
Description: A hardcoded secret within the software allows an authenticated attacker on an adjacent network to decrypt sensitive data, including user credentials.
Recommendations: Update Ivanti DSM to version 2024.2 or later.

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2024-38648

Affected Products

Ivanti Dsm