CVE-2024-34780

CVSS 3.0 Score 7.2 of 10 (high)

Details

Published Nov 13, 2024
CWE ID 89

Summary

CVE-2024-34780 is a newly disclosed SQL injection vulnerability in Ivanti Endpoint Manager. This issue affects versions prior to the November 2024 Security Update and SU6 November 2022 Security Update. An authenticated attacker with administrative privileges can exploit this flaw to inject malicious SQL code, resulting in remote code execution. Successful exploitation could lead to unauthorized access, data theft, or system compromise. Users are strongly advised to install the latest security updates to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share