CVE-2024-13163
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2024-13163 is a deserialization vulnerability affecting Ivanti Environmental Policy Manager (EPM) versions prior to the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update. This issue permits a remote, unauthenticated attacker to execute arbitrary code on the targeted system, given that local user interaction occurs. The vulnerability stems from the deserialization of untrusted data, providing an opportunity for code injection and subsequent exploitation. This flaw poses a significant risk to affected Ivanti EPM installations and necessitates immediate attention and appropriate security measures.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.