CVE-2024-8191: SQL Injection
Published Sep 10, 2024
·Updated
SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.
Affected Software
8 affected components
Ivanti Endpoint Manager<2022
Ivanti Endpoint Manager=2022
Ivanti Endpoint Manager=2022-su1
Ivanti Endpoint Manager=2022-su2
Ivanti Endpoint Manager=2022-su3
Ivanti Endpoint Manager=2022-su4
Ivanti Endpoint Manager=2022-su5
Ivanti Endpoint Manager=2024
Event History
Sep 10, 2024
CVE Published
via MITRE·08:50 PM
Data Sourced
via MITRE·08:50 PM
DescriptionSeverityWeakness
Jul 4, 56726
Event
via FIRST·01:16 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-8191?
CVE-2024-8191 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2024-8191?
To remediate CVE-2024-8191, upgrade Ivanti Endpoint Manager to version 2022 SU6 or the September 2024 update.
3
Which versions of Ivanti Endpoint Manager are affected by CVE-2024-8191?
CVE-2024-8191 affects Ivanti Endpoint Manager versions prior to 2022 SU6 and the 2024 September update.
4
Can CVE-2024-8191 be exploited by unauthenticated users?
Yes, CVE-2024-8191 can be exploited by remote unauthenticated attackers.
5
What type of vulnerability is CVE-2024-8191 classified as?
CVE-2024-8191 is classified as an SQL injection vulnerability.