Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-38648


A hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent network to decrypt sensitive data including user credentials.


Published

2025-07-12T04:15:46.313

Last Modified

2025-07-17T13:36:47.773

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.7 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-798

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ivanti desktop_\&_server_management < 2024.2 Yes

References