Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
CVE-2024-10256 Details
Description
Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 10, 2024Exploitation: NoneAutomatable: NoTechnical Impact: Partial
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Patch-SDK-CVE-2024-10256 | ivanti | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-732 | Incorrect Permission Assignment for Critical Resource | ivanti |
Affected Products
| Product | Versions |
|---|---|
| ivanti endpoint manager | 2022 - 2022 su1 2022 su2 2022 su3 2022 su4 2022 su5 2022 su6 2024 - |
CPE
Remediation
| |
| ivanti neurons agent platform | < 2024.4 |
CPE
Remediation
| |
| ivanti neurons for patch management | < 2024.4 |
CPE
Remediation
| |
| ivanti patch for configuration manager | < 2024.4 |
CPE
Remediation
| |
| ivanti patch software development kit | < 9.7.703 |
CPE
Remediation
| |
| ivanti security controls | < 2024.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ivanti |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 12, 2025 | Initial Analysis | [email protected] |
| Dec 10, 2024 | New CVE Received | ivanti |