Remote Code Execution Vulnerability in Ivanti EPM Management Console
CVE-2024-8191
9.8CRITICAL
Summary
A vulnerability exists in the management console of Ivanti Endpoint Manager that allows remote unauthenticated attackers to exploit an SQL injection flaw. This vulnerability affects versions of Ivanti EPM released before the 2022 SU6 update as well as the September 2024 update. Successfully exploiting this flaw can enable attackers to execute arbitrary code on the affected systems, posing a serious risk to data integrity and system security.
Affected Version(s)
Endpoint Manager 2022 SU6
Endpoint Manager 2022 SU6
Endpoint Manager 2024 September Security Update
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published