Ivanti Endpoint Manager
cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*
- <= 2022 SU8 Security Update 1
- <= 2024 SU3
A remote code execution vulnerability has been identified in Ivanti Endpoint Manager (EPM) versions 2022 SU8 Security Update 1 and prior, as well as in EPM 2024 SU3 and prior. This vulnerability arises from insufficient filename validation, allowing remote unauthenticated attackers to execute code. Exploitation of this issue requires user interaction.
Exploitation of this vulnerability allows for remote code execution on the affected system.
Users can upgrade to Ivanti Endpoint Manager 2024 SU3 Security Release 1 or Ivanti Endpoint Manager 2022 SU8 Security Release 2. These versions are available for download in the Ivanti License System (ILS).
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.