Remote Code Execution Vulnerability in Ivanti Endpoint Manager
CVE-2024-37376

7.2HIGH

Key Information:

Vendor

Ivanti

Status
Vendor
CVE Published:
13 November 2024

What is CVE-2024-37376?

The vulnerability involves a SQL injection in Ivanti Endpoint Manager, allowing an attacker with administrative access to execute arbitrary code remotely. This flaw exists in versions that have not received updates as of November 2024 or those prior to the November 2022 Security Update. If exploited, this vulnerability can lead to significant impacts on the security posture of affected environments.

Affected Version(s)

EPM 2024 November Security Update

EPM 2022 SU6 November Security Update

References

EPSS Score

10% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.
CVE-2024-37376 : Remote Code Execution Vulnerability in Ivanti Endpoint Manager