Remote Code Execution Vulnerability in Ivanti Endpoint Manager
CVE-2024-34782

7.2HIGH

Key Information:

Vendor
Ivanti
Status
Vendor
CVE Published:
13 November 2024

Summary

A significant SQL injection vulnerability exists within Ivanti Endpoint Manager, specifically affecting versions that precede the November 2024 Security Update and 2022 SU6 November Security Update. This vulnerability enables an attacker with administrative access to execute arbitrary code remotely, potentially leading to unauthorized control over impacted systems. Organizations utilizing affected versions should prioritize remediation to safeguard against potential exploitation of this vulnerability.

Affected Version(s)

EPM 2024 November Security Update

EPM 2022 SU6 November Security Update

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.