logo

Ivanti warns critical EPM bug lets hackers hijack enrolled devices

ID: d92f36c2-40f8-5fc5-8fca-0bcb62b56b43

STIX ID: report--d92f36c2-40f8-5fc5-8fca-0bcb62b56b43

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-01-04

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Ivanti patched a critical pre-auth SQL injection vulnerability (CVE-2023-39336) in Endpoint Management allowing unauthenticated attackers on internal networks to execute arbitrary SQL and potentially gain control of enrolled devices or achieve remote code execution on the core server; the issue affects all supported EPM versions and was fixed in 2022 Service Update 5. The report also highlights past zero-day Ivanti vulnerabilities exploited by state-affiliated actors against government organizations, underscoring elevated risk to large numbers of organizations that use Ivanti products.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.