CVE-2024-34782

CVSS 3.0 Score 7.2 of 10 (high)

Details

Published Nov 13, 2024
CWE ID 89

Summary

CVE-2024-34782 is a newly disclosed SQL injection vulnerability affecting Ivanti Endpoint Manager prior to the November 2024 Security Update and 2022 SU6 November Security Update. An authenticated attacker with administrative privileges can exploit this flaw, allowing for remote code execution. This issue poses a significant risk to organizations using outdated versions of Ivanti Endpoint Manager, as it enables an attacker to gain unauthorized control over the targeted system. Upgrading to the latest security updates is strongly recommended to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share