ZDI-CAN-25419: ZDI-25-037: Ivanti Endpoint Manager AlertService Improper Input Validation Denial-of-Service Vulnerability
Published Jan 19, 2025
·Updated
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Ivanti Endpoint Manager. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2024-13166.
Affected Software
1 affected component
Ivanti Endpoint Manager
Event History
Jan 19, 2025
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-25419?
The severity of ZDI-CAN-25419 is rated at 7.5 according to the CVSS rating system.
2
What type of attack does ZDI-CAN-25419 enable?
ZDI-CAN-25419 enables remote attackers to create a denial-of-service condition.
3
Do attackers need authentication to exploit ZDI-CAN-25419?
No, authentication is not required to exploit ZDI-CAN-25419.
4
What software is affected by ZDI-CAN-25419?
ZDI-CAN-25419 affects Ivanti Endpoint Manager installations.
5
How can I mitigate ZDI-CAN-25419?
Mitigation steps for ZDI-CAN-25419 include applying any available patches and disabling affected services.