Remote Code Execution Vulnerability in Ivanti Endpoint Manager
CVE-2024-37376
7.2HIGH
What is CVE-2024-37376?
The vulnerability involves a SQL injection in Ivanti Endpoint Manager, allowing an attacker with administrative access to execute arbitrary code remotely. This flaw exists in versions that have not received updates as of November 2024 or those prior to the November 2022 Security Update. If exploited, this vulnerability can lead to significant impacts on the security posture of affected environments.
Affected Version(s)
EPM 2024 November Security Update
EPM 2022 SU6 November Security Update