A race condition in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to modify sensitive configuration files.
https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs
Source: Mitre, NVD
Published: 2024-11-13
Updated: 2024-11-14
Base Score: 3.8
Vector: CVSS2#AV:L/AC:H/Au:S/C:N/I:C/A:N
Severity: Low
Base Score: 4.7
Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
Severity: Medium