CVE-2024-13166
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Jan 14, 2025
CWE ID 787
Summary
CVE-2024-13166 is a newly disclosed vulnerability affecting Ivanti Endpoint Manager (EPM) versions prior to the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update. This issue permits an unauthenticated attacker to execute an out-of-bounds write, leading to a denial of service (DoS) condition. The vulnerability could be exploited remotely, posing a significant risk to organizations using the affected Ivanti EPM versions. It is strongly recommended that users install the latest security updates to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Ivanti Endpoint Manager
Affected Vendors
- Ivanti Software Inc.