CVE-2024-13172: High severity Ivanti EPM vulnerability
Improper signature verification in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13172?
CVE-2024-13172 is considered a critical vulnerability due to its potential for remote code execution by an unauthenticated attacker.
How do I fix CVE-2024-13172?
To mitigate CVE-2024-13172, install the 2024 January-2025 Security Update or the 2022 SU6 January-2025 Security Update from Ivanti.
What software versions are affected by CVE-2024-13172?
CVE-2024-13172 affects Ivanti Endpoint Manager (EPM) versions prior to the 2024 January-2025 Security Update.
Is local user interaction required for exploiting CVE-2024-13172?
Yes, local user interaction is required for an attacker to exploit CVE-2024-13172 to achieve remote code execution.
Can CVE-2024-13172 be exploited remotely?
Yes, CVE-2024-13172 allows a remote unauthenticated attacker to exploit the vulnerability, but it requires local user interaction.