VDB
CVE-2024-7569
CVE-2024-7569
PUBLISHED
CVSS 9.600000381469727 CRITICAL
An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the OIDC client secret via debug information.
EPSS 7.47% · 91.9th percentile
Risk Scores
CVSS 3.1
9.600000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
EPSS Score
7.47%
91.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ivanti | ITSM | 2023.4, 2023.4.0 |
| ivanti | neurons_for_itsm | 2023.2, 2023.4, 2023.3 |
| ivanti | neurons_for_itsm | 2023.4 |
Timeline
- Aug 13, 2024 CVE Published
- Aug 14, 2024 EPSS Score
- Aug 16, 2024 CVE Updated
- Sep 4, 2024 EPSS Score
- Oct 5, 2024 Coalition ESS Score
- Oct 15, 2024 EPSS Score
- Nov 5, 2024 EPSS Score
- Dec 18, 2024 EPSS Score
- Jan 8, 2025 EPSS Score
- Feb 18, 2025 EPSS Score
- Mar 11, 2025 EPSS Score
- Mar 19, 2025 EPSS Score