Ivanti Endpoint Manager
cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*
- <= 2022 SU8 Security Update 1
- <= 2024 SU3
A remote code execution vulnerability has been identified in Ivanti Endpoint Manager (EPM) versions 2022 SU8 Security Update 1 and prior, as well as in EPM 2024 SU3 and prior. The vulnerability arises from insufficient filename validation, which allows remote unauthenticated attackers to execute code. Exploitation of this vulnerability requires user interaction.
Exploitation of this vulnerability allows for remote code execution on the affected system.
Users can upgrade to Ivanti Endpoint Manager 2024 SU3 Security Release 1 or Ivanti Endpoint Manager 2022 SU8 Security Release 2. Both versions are available for download in the Ivanti License System (ILS).
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.