CVE-2024-34781

CVSS 3.0 Score 7.2 of 10 (high)

Details

Published Nov 13, 2024
CWE ID 89

Summary

CVE-2024-34781: Ivanti Endpoint Manager contains an SQL injection vulnerability. An authenticated attacker with administrative privileges can exploit this issue, which exists in versions prior to the November 2024 Security Update and 2022 SU6, leading to remote code execution. This puts organizational networks at risk for potential data breaches and unauthorized system access. Attackers can inject malicious SQL queries, bypassing input validation, and execute arbitrary commands, potentially resulting in significant damage. It is recommended that users install the latest security updates as soon as possible to mitigate the threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share