logo

Multiple Vulnerabilities in Ivanti Endpoint Manager Could Allow for Remote Code Execution

ID: 7dd97b37-97b7-5cf6-9d66-c42a560414b2

STIX ID: report--7dd97b37-97b7-5cf6-9d66-c42a560414b2

Feed Name: CISecurity.org Advisories

Threat Score
75/100

Date Published: 2024-11-13

Date Updated: 2026-04-27

...
...

Multiple SQL injection and path traversal vulnerabilities (including CVE-2024-50330 and CVE-2024-50329 among others) were disclosed in Ivanti Endpoint Manager; some allow remote unauthenticated attackers to achieve remote code execution, while others require authentication or user interaction. Affected versions are those prior to the 2024 November Security Update or 2022 SU6 November Security Update; successful exploitation could permit installation of programs and viewing, modification, or deletion of data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.