CVE-2024-13171

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 434

Summary

CVE-2024-13171 is a newly disclosed vulnerability affecting Ivanti Endpoint Manager (EPM) before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update. This issue stems from insufficient filename validation, enabling a remote, unauthenticated attacker to execute arbitrary code on targeted systems. Interaction from a local user is necessary for the exploitation of this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share