Secure Access Client

Vendor:

First CVE: Oct 25, 2023 · Active for 2 years

21
Total CVEs
More Total CVEs than 94% of tracked products
5.3
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Secure Access Client over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 25, 2023
2 years ago
Most Recent CVE
May 22, 2026
66 days ago

CVE Severity & Scoring

Secure Access Client21 CVEs
All CVEs352,785 CVEs
LowMediumHigh
Attack Vector
Local20 (95.2%)
Network1 (4.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (85.7%)
High3 (14.3%)
Unknown0 (0.0%)
User Interaction
None19 (90.5%)
Unknown0 (0.0%)
Required2 (9.5%)
Privileges Required
Low19 (90.5%)
High1 (4.8%)
None1 (4.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code.
May 22, 20268.835NONO
A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM
May 12, 20267.028NONO
Insufficiently restrictive permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.
Mar 11, 20257.824NONO
Pulse Secure Client SetupService Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installa
May 3, 20247.823NONO
A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration,
Nov 15, 20237.823NONO
A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentiall
Nov 15, 20237.823NONO
A local privilege escalation vulnerability in Ivanti Secure Access Client for Linux before 22.7R1, allows a low privileged user to execute code as root.
May 31, 20247.322NONO
A local privilege escalation vulnerability in Ivanti Secure Access Client for Windows allows a low privileged user to execute code as SYSTEM.
May 31, 20247.822NONO
When a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the affected system when having control over a specific file.
Nov 15, 20237.822NONO
A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration,
Nov 15, 20237.822NONO

Exploit Exposure

Signals from CVEs in this product scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (21 CVEs).

Media Mentions

Signals from CVEs in this product scope (21 CVEs).

Top CNAs Publishing CVEs For Secure Access Client

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
22.836.70.3%00
22.786.00.3%00
22.637.80.5%00
22.336.90.5%00
22.237.00.6%00