A hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent network to decrypt sensitive data including user credentials.
2025-07-12T04:15:46.313
2025-07-17T13:36:47.773
Analyzed
CVSSv3.1: 5.7 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ivanti | desktop_\&_server_management | < 2024.2 | Yes |