Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-49768 | Under specific circumstances, insecure permissions in Ivanti Velocity License Server before version 5.2 allows a local authenticated attacker to achieve local privilege escalation. |
Mon, 04 Nov 2024 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 08 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ivanti
Ivanti velocity License Server |
|
| CPEs | cpe:2.3:a:ivanti:velocity_license_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ivanti
Ivanti velocity License Server |
|
| Metrics |
ssvc
|
Tue, 08 Oct 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Under specific circumstances, insecure permissions in Ivanti Velocity License Server before version 5.2 allows a local authenticated attacker to achieve local privilege escalation. | |
| Weaknesses | CWE-276 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ivanti
Published:
Updated: 2024-11-04T14:25:55.828Z
Reserved: 2024-09-24T19:21:30.463Z
Link: CVE-2024-9167
Updated: 2024-10-08T18:53:52.876Z
Status : Analyzed
Published: 2024-10-08T17:15:56.517
Modified: 2025-08-13T00:22:52.960
Link: CVE-2024-9167
No data.
OpenCVE Enrichment
No data.
EUVD