CVE-2024-34783: SQL Injection
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34783?
CVE-2024-34783 is considered critical due to its potential for remote code execution by an authenticated attacker with admin privileges.
How do I fix CVE-2024-34783?
To mitigate CVE-2024-34783, ensure you update your Ivanti EPM to the latest version or apply the September 2024 patch.
What are the affected versions for CVE-2024-34783?
CVE-2024-34783 affects Ivanti Endpoint Manager versions prior to 2022 SU6 and the September 2024 update.
What type of vulnerability is CVE-2024-34783?
CVE-2024-34783 is an unspecified SQL injection vulnerability that enables remote code execution.
Who is at risk for CVE-2024-34783?
Organizations using affected versions of Ivanti Endpoint Manager with remote authenticated admin access are at risk for CVE-2024-34783.