Ivanti Endpoint Manager
cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*
- <= 2024 SU4
A vulnerability exists in the patch management component of Ivanti Endpoint Manager, affecting versions through 2024 SU4 and prior. This vulnerability arises from improper verification of cryptographic signatures, which allows a remote, unauthenticated attacker to execute arbitrary code. Exploitation of this vulnerability requires user interaction.
Exploitation of this vulnerability allows for arbitrary code execution on the affected system.
Users can upgrade to Ivanti Endpoint Manager 2024 SU4 SR1, available for download through the Ivanti License System. This update applies to both core and remote consoles.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.