← Back

CVE-2024-10256

nvd nist
Published: Dec 10, 2024Modified: Jun 17, 2026

JSON object

Loading...
7.1
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Exploitability: 1.8 / Impact: 5.2
Source: 3c1d8aa1-5a33-4ea4-8992-aadd6440af75 (Secondary)

Description

Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.

Affected (13)

6 products
Endpoint Manager
Neurons Agent Platform
Neurons For Patch Management
Patch For Configuration Manager
Patch Software Development Kit
Security Controls
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Ivanti
Version 2022
Version 2022 su1
Version 2022 su2
Version 2022 su3
Version 2022 su4
Version 2022 su5
Version 2022 su6
Version 2024
Before 2024.4
Before 2024.4
Before 2024.4
Before 9.7.703
Before 2024.4

References (1)

Source: 3c1d8aa1-5a33-4ea4-8992-aadd6440af75
MitigationVendor Advisory

Timeline

No history available yet.