First published: Tue Nov 14 2023(Updated: )
A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti Secure Access Client | <22.6 | |
Ivanti Secure Access Client | =22.6-r1 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-38543.
The title of this vulnerability is 'A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1 which could...'.
CVE-2023-38543 has a severity rating of 8.8 (High).
This vulnerability affects all versions of the Ivanti Secure Access Client below 22.6R1.1.
This vulnerability could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine.
You can find more information about this vulnerability at the following references: [Reference 1](https://forums.ivanti.com/s/article/Security-fixes-included-in-the-latest-Ivanti-Secure-Access-Client-Release), [Reference 2](https://northwave-cybersecurity.com/vulnerability-notice/denial-of-service-in-ivanti-secure-access-client-driver)