CISA Adds High-Severity Ivanti Vulnerability to KEV Catalog
ID: 6b32dc91-8f77-5633-bd04-3b16e5d48dbc
STIX ID: report--6b32dc91-8f77-5633-bd04-3b16e5d48dbc
Feed Name: Dark Reading
Threat Score
A critical SQL injection vulnerability (CVE-2024-29824) in Ivanti Endpoint Manager (core server) allows unauthenticated attackers on the network to achieve arbitrary code execution; it has a CVSS score of 9.6 and Ivanti reported a limited number of customers were exploited in the wild. Ivanti released security updates and guidance for patching, and the advisory urges organizations to prioritize immediate patching and thorough security assessments to mitigate potential compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
