CVE-2024-38648: Critical severity Ivanti DSM vulnerability
Published Jul 12, 2025
·Updated
A hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent network to decrypt sensitive data including user credentials.
Affected Software
2 affected components
Ivanti DSM<2024.2
Ivanti Desktop \& Server Management<2024.2
Event History
Jul 12, 2025
CVE Published
via MITRE·03:30 AM
Data Sourced
via MITRE·03:30 AM
DescriptionSeverity
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-38648?
CVE-2024-38648 has been classified as a high-severity vulnerability due to the potential exposure of sensitive data.
2
How do I fix CVE-2024-38648?
To mitigate CVE-2024-38648, upgrade your Ivanti DSM to version 2024.2 or later.
3
Who is impacted by CVE-2024-38648?
CVE-2024-38648 affects users of Ivanti DSM versions prior to 2024.2.
4
What type of attack vectors are associated with CVE-2024-38648?
CVE-2024-38648 allows authenticated attackers on adjacent networks to exploit hardcoded secrets and decrypt sensitive information.
5
What data can be exposed due to CVE-2024-38648?
CVE-2024-38648 can lead to the exposure of sensitive data, including user credentials.