Ivanti Endpoint Manager
cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*
- <= 2024 SU4 SR1
This vulnerability is being actively exploited in the wild.
A vulnerability allowing authentication bypass has been identified in Ivanti Endpoint Manager (EPM) versions 2024 SU4 SR1 and prior. This vulnerability enables remote, unauthenticated attackers to leak specific stored credential data.
Exploitation of this vulnerability could lead to unauthorized access to sensitive credential information.
Users can update to Ivanti Endpoint Manager 2024 SU5 to address this vulnerability. The update is available through the Ivanti License System (ILS).
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.