Ivanti has released security updates to address multiple critical flaws in its Cloud Services Application (CSA) and Connect Secure products that could lead to privilege escalation and code execution.
The list of vulnerabilities is as follows -
CVE-2024-11639 (CVSS score: 10.0) - An authentication bypass vulnerability in the admin web console of Ivanti CSA before 5.0.3 that allows a remote
A vulnerability has been found in G Data Total Security and classified as critical. This vulnerability affects unknown code. The manipulation leads to permission issues.
This vulnerability was named CVE-2024-6871. The attack needs to be approached locally. There is no exploit available.
A vulnerability was found in Siemens Tecnomatix Plant Simulation. It has been classified as critical. This affects an unknown part of the component WRL File Handler. The manipulation leads to out-of-bounds write.
This vulnerability is uniquely identified as CVE-2024-52566. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.