Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54777 | A hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent network to decrypt sensitive data including user credentials. |
Thu, 17 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ivanti
Ivanti desktop \& Server Management |
|
| CPEs | cpe:2.3:a:ivanti:desktop_\&_server_management:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ivanti
Ivanti desktop \& Server Management |
|
| Metrics |
cvssV3_1
|
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 14 Jul 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-798 | |
| Metrics |
ssvc
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
Sat, 12 Jul 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent network to decrypt sensitive data including user credentials. | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2025-07-14T16:12:29.434Z
Reserved: 2024-06-19T01:04:07.137Z
Link: CVE-2024-38648
Updated: 2025-07-14T16:11:53.179Z
Status : Analyzed
Published: 2025-07-12T04:15:46.313
Modified: 2025-07-17T13:36:47.773
Link: CVE-2024-38648
No data.
OpenCVE Enrichment
No data.
EUVD