VDB
CVE-2024-7570
CVE-2024-7570
PUBLISHED
CVSS 8.100000381469727 HIGH
Improper certificate validation in Ivanti ITSM on-prem and Neurons for ITSM Versions 2023.4 and earlier allows a remote attacker in a MITM position to craft a token that would allow access to ITSM as any user.
EPSS 1.83% · 83.3th percentile
Risk Scores
CVSS 3.1
8.100000381469727
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
1.83%
83.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ivanti | neurons_for_itsm | 0 |
| Ivanti | ITSM | 2023.4.0, 2023.4 |
| ivanti | neurons_for_itsm | 2023.2, 2023.3, 2023.4 |
Timeline
- Aug 13, 2024 CVE Published
- Aug 14, 2024 EPSS Score
- Aug 16, 2024 CVE Updated
- Sep 4, 2024 EPSS Score
- Sep 25, 2024 EPSS Score
- Oct 5, 2024 Coalition ESS Score
- Oct 15, 2024 EPSS Score
- Nov 5, 2024 EPSS Score
- Dec 18, 2024 EPSS Score
- Jan 8, 2025 EPSS Score
- Jan 28, 2025 EPSS Score
- Feb 18, 2025 EPSS Score