← Back

CVE-2024-7570

nvd nist
Published: Aug 13, 2024Modified: Sep 6, 2024

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD

Description

Improper certificate validation in Ivanti ITSM on-prem and Neurons for ITSM Versions 2023.4 and earlier allows a remote attacker in a MITM position to craft a token that would allow access to ITSM as any user.

Affected (3)

1 product
Neurons For Itsm
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Ivanti
Version 2023.2
Version 2023.3
Version 2023.4

References (1)

Timeline

No history available yet.