CVE-2024-13165

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 787

Summary

CVE-2024-13165 is a newly identified vulnerability affecting Ivanti Enterprise Performance Manager (EPM) versions prior to the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update. An out-of-bounds write flaw in the software enables a remote, unauthenticated attacker to trigger a denial-of-service condition. By exploiting this vulnerability, cybercriminals can cause the targeted system to crash or become unresponsive, potentially leading to disruptions in business operations. It is strongly recommended that users install the available security updates to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share