EXECUTIVE SUMMARY
Ivanti has resolved ten security vulnerabilities in its Endpoint Manager (EPM), six of which are critical-severity SQL Injection vulnerabilities. Tracked as CVE-2024-29822 through CVE-2024-29827, these bugs affect the Core server of Ivanti EPM 2022 SU5 and earlier versions, with a CVSS score of 9.6. These vulnerabilities could allow an unauthenticated attacker on the network to execute arbitrary code. Ivanti has released hot fixes for EPM 2022 SU5 and provided detailed instructions for customers to update their systems.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
Ivanti has resolved ten security vulnerabilities in its Endpoint Manager (EPM), six of which are critical-severity SQL Injection vulnerabilities. Tracked as CVE-2024-29822 through CVE-2024-29827, these bugs affect the Core server of Ivanti EPM 2022 SU5 and earlier versions, with a CVSS score of 9.6. These vulnerabilities could allow an unauthenticated attacker on the network to execute arbitrary code. Ivanti has released hot fixes for EPM 2022 SU5 and provided detailed instructions for customers to update their systems.[emaillocker id="1283"]
The hot fixes also address four other high-severity SQL injection vulnerabilities in EPM 2022 SU5 and prior releases, which could similarly be exploited to execute arbitrary code without authentication. Moreover, Ivanti announced patches for a high-severity unrestricted file upload vulnerability in the web component of Ivanti Avalanche, which could allow attackers to execute code with System privileges.
The company has released necessary hot fixes and patches to mitigate these security risks and urges users to update their systems promptly. Despite the severity of the vulnerabilities, Ivanti has found no evidence of them being exploited in attacks, emphasizing the importance of timely updates to maintain security.
RECOMMENDATION:
REFERENCES:
The following reports contain further technical details:
[/emaillocker]