This page lists publicly disclosed CVE vulnerabilities affecting ivanti security_controls (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2024-10630 | A race condition in Ivanti Application Control Engine before version 10.14.4.0 allows a local authenticated attacker to bypass the application blocking functionality. | 3c1d8aa1-5a33-4ea4-8992-aadd6440af75 | 7.8 | 0.22% | 2025-01-14 | 2026-06-17 |
| CVE-2024-10251 | Under specific circumstances, insecure permissions in Ivanti Security Controls before version 2024.4.1 allows a local authenticated attacker to achieve local privilege escalation. | 3c1d8aa1-5a33-4ea4-8992-aadd6440af75 | 7.8 | 0.21% | 2024-12-11 | 2026-06-17 |
| CVE-2024-10256 | Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files. | 3c1d8aa1-5a33-4ea4-8992-aadd6440af75 | 7.1 | 0.21% | 2024-12-10 | 2026-06-17 |