CVE-2022-21823: Medium severity ivanti workspace control vulnerability
Published Jan 7, 2022
·Updated
A insecure storage of sensitive information vulnerability exists in Ivanti Workspace Control <2021.2 (10.7.30.0) that could allow an attacker with locally authenticated low privileges to obtain key information due to an unspecified attack vector.
Affected Software
1 affected component
Ivanti Workspace Control<10.7.30.0
Remediation
Event History
Jan 7, 2022
CVE Published
via MITRE·10:39 PM
Data Sourced
via MITRE·10:39 PM
DescriptionWeakness
Jan 10, 2022
Data Sourced
via NVD·02:12 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-21823?
The severity of CVE-2022-21823 is medium with a CVSS score of 5.5.
2
What is the vulnerability in Ivanti Workspace Control <2021.2 (10.7.30.0)?
The vulnerability is an insecure storage of sensitive information vulnerability.
3
How does the vulnerability in Ivanti Workspace Control <2021.2 (10.7.30.0) occur?
The vulnerability occurs due to an unspecified attack vector.
4
Who is affected by CVE-2022-21823?
Users of Ivanti Workspace Control versions prior to 2021.2 (10.7.30.0) are affected.
5
How can an attacker exploit CVE-2022-21823?
A locally authenticated attacker with low privileges can exploit the vulnerability to obtain key information.