CVE-2024-13168: High severity ivanti endpoint manager (epm) vulnerability
An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13168?
CVE-2024-13168 is classified as a high severity vulnerability due to its potential to allow remote unauthenticated attackers to cause a denial of service.
How do I fix CVE-2024-13168?
To fix CVE-2024-13168, you should upgrade your Ivanti EPM software to the 2024 January-2025 Security Update or the 2022 SU6 January-2025 Security Update.
What are the consequences of exploiting CVE-2024-13168?
Exploiting CVE-2024-13168 allows an attacker to perform an out-of-bounds write, resulting in a denial of service for affected systems.
Which versions of Ivanti EPM are affected by CVE-2024-13168?
Ivanti EPM versions prior to the 2024 January-2025 Security Update and the 2022 SU6 January-2025 Security Update are affected by CVE-2024-13168.
Is CVE-2024-13168 a local or remote vulnerability?
CVE-2024-13168 is a remote vulnerability that does not require authentication to exploit.