Attackers Can Modify Sensitive Configuration Files via Race Condition in Ivanti Secure Access Client
CVE-2024-29211

4.7MEDIUM

Key Information:

Vendor
Ivanti
Vendor
CVE Published:
13 November 2024

Summary

A vulnerability exists within the Ivanti Secure Access Client due to a race condition that enables local authenticated attackers to alter critical configuration files. This could lead to the unauthorized modification of settings essential for security and functionality, thereby compromising system integrity and security policies.

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

Collectors

NVD Database
.