CVE-2024-34779: SQL Injection
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34779?
CVE-2024-34779 has been classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2024-34779?
To mitigate CVE-2024-34779, update Ivanti Endpoint Manager to version 2022 SU6 or later as well as the 2024 September update.
Who is affected by CVE-2024-34779?
CVE-2024-34779 affects users of Ivanti Endpoint Manager versions prior to 2022 SU6 and the 2024 September update.
What type of attack does CVE-2024-34779 enable?
CVE-2024-34779 enables a remote authenticated attacker with admin privileges to perform SQL injection and potentially achieve remote code execution.
Is there any workaround for CVE-2024-34779?
There are no known workarounds for CVE-2024-34779; patching the software is the recommended approach.