CVE-2024-13166: High severity ivanti endpoint manager (epm) vulnerability
An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13166?
CVE-2024-13166 is considered a high-severity vulnerability due to its potential to allow remote unauthenticated attackers to cause a denial of service.
How do I fix CVE-2024-13166?
To mitigate CVE-2024-13166, you should update your Ivanti EPM to the 2024 January-2025 Security Update or the 2022 SU6 January-2025 Security Update.
What types of attacks can exploit CVE-2024-13166?
CVE-2024-13166 can be exploited by remote unauthenticated attackers to perform denial of service attacks on vulnerable systems.
Which versions of Ivanti EPM are affected by CVE-2024-13166?
CVE-2024-13166 affects Ivanti EPM versions prior to the 2024 January-2025 Security Update and the 2022 SU6 January-2025 Security Update.
Can CVE-2024-13166 be exploited without authentication?
Yes, CVE-2024-13166 can be exploited by remote attackers without requiring any form of authentication.