Path Traversal Vulnerability in Ivanti Endpoint Manager
CVE-2024-50329

8.8HIGH

Key Information:

Vendor
Ivanti
Vendor
CVE Published:
12 November 2024

Summary

A path traversal vulnerability in Ivanti Endpoint Manager allows remote unauthenticated attackers to execute arbitrary code on affected systems. This security flaw exists in versions released before the November 2024 Security Update and the November Security Update for SU6 of 2022. Due to the nature of the vulnerability, user interaction is required, complicating the exploit but still leaving systems at risk without adequate mitigation strategies. Organizations utilizing Ivanti Endpoint Manager are urged to apply the latest security updates promptly to safeguard against potential exploits.

Affected Version(s)

Endpoint Manager 2024 November Security Update

Endpoint Manager 2024 November Security Update

Endpoint Manager 2022 SU6 November Security Update

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.