ZDI-CAN-25415: ZDI-25-033: Ivanti Endpoint Manager AlertService Improper Input Validation Denial-of-Service Vulnerability
Published Jan 19, 2025
·Updated
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Ivanti Endpoint Manager. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2024-13170.
Affected Software
1 affected component
Ivanti Endpoint Manager
Event History
Jan 19, 2025
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-25415?
The severity of ZDI-CAN-25415 is rated at 7.5 according to CVSS.
2
What type of attack does ZDI-CAN-25415 allow?
ZDI-CAN-25415 allows remote attackers to create a denial-of-service condition on affected installations.
3
Is authentication required to exploit ZDI-CAN-25415?
No, authentication is not required to exploit ZDI-CAN-25415.
4
Which software is affected by ZDI-CAN-25415?
ZDI-CAN-25415 affects Ivanti Endpoint Manager installations.
5
How can I mitigate the risks associated with ZDI-CAN-25415?
To mitigate the risks of ZDI-CAN-25415, it's important to apply all relevant security patches provided by Ivanti.