CVE-2024-29213: High severity ivanti desktop and server management vulnerability
Published Oct 18, 2024
·Updated
Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector.
Affected Software
2 affected components
Ivanti DSM<2024.2
Ivanti Desktop \& Server Management<2024.2
Event History
Oct 18, 2024
CVE Published
via MITRE·11:06 PM
Data Sourced
via MITRE·11:06 PM
DescriptionSeverity
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-29213?
CVE-2024-29213 is considered a high severity vulnerability due to the potential for authenticated users to execute code with elevated privileges.
2
How do I fix CVE-2024-29213?
To mitigate CVE-2024-29213, upgrade Ivanti DSM to version 2024.2 or later to ensure secure access control lists are in place.
3
Who is affected by CVE-2024-29213?
CVE-2024-29213 affects users of Ivanti DSM versions prior to 2024.2 on local machines.
4
What type of vulnerability is CVE-2024-29213?
CVE-2024-29213 is classified as a code execution vulnerability due to insecure access control settings.
5
What are the potential risks of CVE-2024-29213?
The risks of CVE-2024-29213 include unauthorized code execution and possible system compromise by authenticated users.