UnAuthenticated Code Execution Vulnerability in Ivanti Endpoint Manager
CVE-2024-34787
7.8HIGH
Summary
A path traversal vulnerability exists in Ivanti Endpoint Manager, which can allow a local unauthenticated attacker to execute arbitrary code. This vulnerability affects versions prior to the November 2024 Security Update and the 2022 SU6 November Security Update. User interaction is necessary for the exploit to succeed, making it imperative for users and administrators to ensure they are operating on the latest software updates to mitigate this security risk. For more details, refer to the official security advisory.
Affected Version(s)
EPM 2024 November Security Update
EPM 2022 SU6 November Security Update
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Collectors
NVD DatabaseMitre Database