Remote Code Execution Vulnerability in Ivanti Endpoint Manager
CVE-2024-37376
7.2HIGH
Summary
The vulnerability involves a SQL injection in Ivanti Endpoint Manager, allowing an attacker with administrative access to execute arbitrary code remotely. This flaw exists in versions that have not received updates as of November 2024 or those prior to the November 2022 Security Update. If exploited, this vulnerability can lead to significant impacts on the security posture of affected environments.
Affected Version(s)
EPM 2024 November Security Update
EPM 2022 SU6 November Security Update
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published