Remote Code Execution Vulnerability in Ivanti Endpoint Manager
CVE-2024-34782

7.2HIGH

Key Information:

Vendor

Ivanti

Status
Vendor
CVE Published:
13 November 2024

What is CVE-2024-34782?

A significant SQL injection vulnerability exists within Ivanti Endpoint Manager, specifically affecting versions that precede the November 2024 Security Update and 2022 SU6 November Security Update. This vulnerability enables an attacker with administrative access to execute arbitrary code remotely, potentially leading to unauthorized control over impacted systems. Organizations utilizing affected versions should prioritize remediation to safeguard against potential exploitation of this vulnerability.

Affected Version(s)

EPM 2024 November Security Update

EPM 2022 SU6 November Security Update

References

EPSS Score

10% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.