CVE-2024-13162
largeAuthenticated SQL Injection to RCE in Ivanti Endpoint Manager (EPM)
CVE-2024-13162 is a SQL injection (CWE-89) in Ivanti Endpoint Manager (EPM) that completes fixes left incomplete by the earlier patch for CVE-2024-32848. A remote attacker who already holds administrator credentials on the EPM deployment can send crafted input to the database layer over the network (AV:N, low complexity, high privileges required), triggering the injection. Successful exploitation escalates to arbitrary remote code execution on the EPM server, with high impact to confidentiality, integrity, and availability. Organizations running EPM 2024 or EPM 2022 SU6 without the January 2025 Security Update are affected. No public proof-of-concept or CISA KEV listing is known yet, but the flaw sits in the 99th EPSS percentile with a 64.2% predicted probability of exploitation within 30 days, so it is considered very likely to be attacked soon.
What to do: Apply the January-2025 Security Update for EPM 2024 and the January-2025 Security Update for EPM 2022 SU6, and confirm systems that already took earlier updates for CVE-2024-32848 also receive this January-2025 rollup, since it completes the incomplete prior fix. Restrict administrative access to the EPM core server and console, and review privileged accounts for signs of compromise given the high predicted exploitation likelihood.
| Ivanti Endpoint Manager (EPM) 2024 | All versions prior to the EPM 2024 January-2025 Security Update |
| Ivanti Endpoint Manager (EPM) 2022 SU6 | All versions prior to the EPM 2022 SU6 January-2025 Security Update |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
SQL injection in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. This CVE addresses incomplete fixes from CVE-2024-32848.
- Vendors
- ivanti
- Products
- endpoint manager
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.