Remote Code Execution Vulnerability in Ivanti Endpoint Manager
CVE-2024-34782
7.2HIGH
Summary
A significant SQL injection vulnerability exists within Ivanti Endpoint Manager, specifically affecting versions that precede the November 2024 Security Update and 2022 SU6 November Security Update. This vulnerability enables an attacker with administrative access to execute arbitrary code remotely, potentially leading to unauthorized control over impacted systems. Organizations utilizing affected versions should prioritize remediation to safeguard against potential exploitation of this vulnerability.
Affected Version(s)
EPM 2024 November Security Update
EPM 2022 SU6 November Security Update
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published