CVE-2024-34781
CVSS 3.0 Score 7.2 of 10 (high)
Details
Summary
CVE-2024-34781: Ivanti Endpoint Manager contains an SQL injection vulnerability. An authenticated attacker with administrative privileges can exploit this issue, which exists in versions prior to the November 2024 Security Update and 2022 SU6, leading to remote code execution. This puts organizational networks at risk for potential data breaches and unauthorized system access. Attackers can inject malicious SQL queries, bypassing input validation, and execute arbitrary commands, potentially resulting in significant damage. It is recommended that users install the latest security updates as soon as possible to mitigate the threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Ivanti Endpoint Manager