First published: Tue Sep 10 2024(Updated: )
Cleartext transmission of sensitive information in the management console of Ivanti Workspace Control version 10.18.0.0 and below allows a local authenticated attacker to obtain OS credentials.
Credit: 3c1d8aa1-5a33-4ea4-8992-aadd6440af75
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti Workspace Control | <10.18.99.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-44105 is rated as a high severity vulnerability due to the potential exposure of sensitive OS credentials.
To remediate CVE-2024-44105, upgrade Ivanti Workspace Control to version 10.18.1000 or above.
CVE-2024-44105 affects users of Ivanti Workspace Control version 10.18.0.0 and below.
CVE-2024-44105 involves a local authenticated attacker exploiting cleartext transmission to capture OS credentials.
CVE-2024-44105 is primarily a local vulnerability as it requires authenticated access to the management console.