PT-2024-6662 · Ivanti · Ivanti Workspace Control

CVE-2024-44105

·

Published

2024-09-10

·

Updated

2025-06-12

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Ivanti Workspace Control versions 10.18.0.0 and below
Description: The issue is related to the transmission of sensitive information in cleartext, allowing a local authenticated attacker to obtain operating system credentials. This can be exploited to gain unauthorized access to the system.
Recommendations: For Ivanti Workspace Control versions 10.18.0.0 and below, update to a version above 10.18.0.0 to resolve the issue. As a temporary workaround, consider restricting access to the management console to minimize the risk of exploitation.

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-07864
CVE-2024-44105

Affected Products

Ivanti Workspace Control