Remote Code Execution Vulnerability in Ivanti EPM Before 2022 SU6 and 2024 September Update
CVE-2024-34785
What is CVE-2024-34785?
An unspecified vulnerability in Ivanti Endpoint Manager prior to the 2022 SU6 update and the September 2024 release can be exploited through SQL injection. This weakness allows a remote authenticated user with administrative privileges to execute arbitrary code on the affected system. Malicious actors can leverage this vulnerability to compromise the integrity and confidentiality of the system, highlighting the need for prompt updates and security measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
EPM 2024 September Security Update
EPM 2022 SU6
References
EPSS Score
32% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved