ZDI-CAN-25929: ZDI-25-041: Ivanti Endpoint Manager updateAssetInfo SQL Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Endpoint Manager. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2024-13162.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-25929?
ZDI-CAN-25929 has a CVSS rating of 7.2, indicating a high severity level.
How can I exploit ZDI-CAN-25929?
Exploitation of ZDI-CAN-25929 requires authentication to execute arbitrary code on affected installations.
What is the impact of ZDI-CAN-25929 on Ivanti Endpoint Manager?
The impact of ZDI-CAN-25929 is the potential for remote attackers to execute arbitrary code on affected installations.
How do I remediate ZDI-CAN-25929?
To remediate ZDI-CAN-25929, ensure that your Ivanti Endpoint Manager is updated to the latest version provided by the vendor.
Which versions of Ivanti Endpoint Manager are affected by ZDI-CAN-25929?
ZDI-CAN-25929 affects all installations of Ivanti Endpoint Manager that have not been updated against this vulnerability.