CVE-2024-38648 PUBLISHED

Assigner: hackerone
Reserved: 19.06.2024 Published: 12.07.2025 Updated: 14.07.2025

A hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent network to decrypt sensitive data including user credentials.

Metrics

CVSS Vector: CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 9

Product Status

Vendor Ivanti
Product DSM
Versions Default: unaffected
  • affected from 2024.2 to 2024.2 (excl.)

References