CVE-2024-8322: High severity ivanti endpoint manager (epm) vulnerability
Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker to access restricted functionality.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8322?
CVE-2024-8322 has been classified with a moderate severity due to the potential for unauthorized access to restricted features.
How do I fix CVE-2024-8322?
To fix CVE-2024-8322, upgrade to Ivanti Endpoint Manager version 2022 SU6 or apply the September 2024 update.
Which versions of Ivanti Endpoint Manager are affected by CVE-2024-8322?
CVE-2024-8322 affects Ivanti Endpoint Manager versions prior to 2022 SU6 and version 2024 before the September update.
What type of attack can CVE-2024-8322 facilitate?
CVE-2024-8322 can potentially allow remote authenticated attackers to exploit weak authentication for unauthorized access.
Is there a patch available for CVE-2024-8322?
Yes, a patch is available through the updates mentioned for Ivanti Endpoint Manager versions 2022 SU6 and the September 2024 release.