CVE-2024-8321: High severity ivanti endpoint manager (epm) vulnerability
Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to isolate managed devices from the network.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8321?
CVE-2024-8321 is considered a critical vulnerability due to its potential to allow remote unauthenticated attackers to isolate managed devices from the network.
How do I fix CVE-2024-8321?
To fix CVE-2024-8321, update to the latest version of Ivanti Endpoint Manager that addresses this vulnerability, specifically any version released after the 2024 September update.
What versions of Ivanti Endpoint Manager are affected by CVE-2024-8321?
CVE-2024-8321 affects all versions of Ivanti Endpoint Manager prior to 2022 SU6 and the 2024 September update.
What impact does CVE-2024-8321 have on managed devices?
CVE-2024-8321 allows an unauthenticated attacker to isolate managed devices from the network, potentially disrupting operations.
Is authentication required for exploiting CVE-2024-8321?
No, CVE-2024-8321 can be exploited without any form of authentication.