← Back

Desktop & Server Management

desktop_&_server_management

Vendor: Ivanti • 6 CVEs

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ivanti
1Desktop & Server Management
Jun 17, 2026
Mar 10, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
An exposed dangerous method in Ivanti DSM before version 2026.1.1 allows a local authenticated attacker to escalate their privileges.
1Ivanti
1Desktop & Server Management
Jun 17, 2026
Jul 12, 2025
N/A· v4
5.7 MEDIUM· v3
N/A· v2
A hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent network to decrypt sensitive data including user credentials.
1Ivanti
1Desktop & Server Management
Jun 17, 2026
Dec 10, 2024
N/A· v4
7.1 HIGH· v3
N/A· v2
Insufficient permissions in Ivanti DSM before version 2024.3.5740 allows a local authenticated attacker to delete arbitrary files.
1Ivanti
1Desktop & Server Management
Jun 17, 2026
Oct 18, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector.
1Ivanti
1Desktop & Server Management
Jun 17, 2026
Oct 18, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector.
1Ivanti
1Desktop & Server Management
Jun 17, 2026
Aug 10, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
DSM 2022.2 SU2 and all prior versions allows a local low privileged account to execute arbitrary OS commands as the DSM software installation user.