UnAuthenticated Code Execution Vulnerability in Ivanti Endpoint Manager
CVE-2024-34787

7.8HIGH

Key Information:

Vendor
Ivanti
Status
Vendor
CVE Published:
13 November 2024

Summary

A path traversal vulnerability exists in Ivanti Endpoint Manager, which can allow a local unauthenticated attacker to execute arbitrary code. This vulnerability affects versions prior to the November 2024 Security Update and the 2022 SU6 November Security Update. User interaction is necessary for the exploit to succeed, making it imperative for users and administrators to ensure they are operating on the latest software updates to mitigate this security risk. For more details, refer to the official security advisory.

Affected Version(s)

EPM 2024 November Security Update

EPM 2022 SU6 November Security Update

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

Collectors

NVD DatabaseMitre Database
.