CVE-2022-44569

7.8HIGH

Key Information

Vendor
Ivanti
Status
Automation
Vendor
CVE Published:
3 November 2023

Badges

👾 Exploit Exists

Summary

A locally authenticated attacker with low privileges can bypass authentication due to insecure inter-process communication.

Affected Version(s)

Automation < 2023.4

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit exists.

  • Risk change from: 7.8 to: 8.8 - (HIGH)

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database0 Proof of Concept(s)
.