AI
AI

CISA Includes Critical Ivanti Vulnerability in KEV Catalog

Photo credit: www.darkreading.com

Critical SQL Injection Vulnerability Affects Ivanti Endpoint Manager

The Cybersecurity and Infrastructure Security Agency (CISA) has recently included a new vulnerability, CVE-2024-29824, in its Known Exploited Vulnerabilities Catalog, impacting the Ivanti Endpoint Manager (EPM).

This vulnerability is classified as an SQL Injection flaw located within the core server of Ivanti EPM 2022 SU5 and earlier versions. It permits unauthorized attackers within the network to execute arbitrary code, raising serious security concerns.

Due to its severity, the vulnerability has been assigned a CVSS score of 9.6, marking it as critical.

On October 1, Ivanti released an update to its security advisory, indicating that the vulnerability has already been exploited in the wild. The advisory noted, “At the time of this update, we are aware of a limited number of customers who have been exploited.”

In response to this issue, Ivanti rolled out security updates in May to address this and several other vulnerabilities in the EPM’s core server.

Eric Schwake, the director of cybersecurity strategy at Salt Security, commented on the potential risks associated with this flaw, stating, “Exploiting this flaw could have serious consequences, such as data breaches, disruption of business operations, and further compromise of internal systems.” He urged organizations using Ivanti EPM to prioritize patching their systems without delay and to conduct thorough security evaluations to manage any potential risks effectively. Schwake further emphasized the need for proactive vulnerability management and the importance of timely patching as defenses against evolving cyber threats.

Customers seeking to address this vulnerability can find relevant patching information on Ivanti’s website.

Source
www.darkreading.com

Related by category

Navigating the CISO Cloud Security Dilemma: Purchase, Build, or a Combination of Both?

Photo credit: www.csoonline.com Cloud security is not solely focused on...

Cyberkriminelle optimieren ihre Angriffsstrategien.

Photo credit: www.csoonline.com Cyberkriminalität zielt zunehmend auf kleine und mittelständische...

CNAPP-Kaufberatung

Photo credit: www.csoonline.com Cloud-Sicherheit bleibt ein anspruchsvolles Thema, vor allem,...

Latest news

Top 11 Longchamp Bag Deals on Sale at Gilt

Photo credit: www.travelandleisure.com If you're planning a warm-weather escape or...

Ankita Lokhande Shows Off Adorable Expressions as Vicky Jain and Nia Sharma Dance to ‘3 Peg’ | Watch Now

Photo credit: www.news18.com Last Updated: May 01, 2025, 09:25 IST Ankita...

7-Day Azores Itinerary: Your 2025 Travel Guide

Photo credit: www.adventureinyou.com Looking for a distinct getaway amid lush...

Breaking news