Remote Unauthorized Access to Network Isolation in Ivanti EPM Before 2022 SU6 or 2024 September Update
CVE-2024-8320
Summary
The vulnerability involves a significant missing authentication flaw within the network isolation of Ivanti Endpoint Manager products. This issue permits a remote unauthenticated attacker to exploit the vulnerabilities, enabling them to spoof the network isolation status of managed devices. As a result, attackers can potentially manipulate device visibility and network policies without any authentication, posing a serious risk to the integrity and security of the managed network. Organizations using affected versions of Ivanti EPM should prioritize reviewing security measures and apply the latest updates to mitigate potential risks.
Affected Version(s)
Endpoint Manager 2022 SU6
Endpoint Manager 2022 SU6
Endpoint Manager 2024 September Security Update
References
CVSS V3.1
Timeline
Vulnerability published