CVE-2024-32840
largeAuthenticated SQL Injection Leading to RCE in Ivanti Endpoint Manager
CVE-2024-32840 is an SQL injection vulnerability (CWE-89) in Ivanti Endpoint Manager (EPM) that allows a remote, authenticated attacker with administrator privileges to achieve remote code execution on the EPM server. It is triggered when crafted input reaches a vulnerable database query over the network; no user interaction is required, but the attacker must already hold admin-level credentials. Successful exploitation yields high-impact compromise of the server (confidentiality, integrity and availability all rated high), giving the attacker code execution on the EPM core server. Organizations running EPM 2022 before Service Update 6, or EPM 2024 before the September 2024 update, are affected. There is no confirmed exploitation, no public proof-of-concept, and the flaw is not in CISA KEV, but its EPSS score of 25.4% (98th percentile) indicates an elevated probability of exploitation within the next 30 days.
What to do: Upgrade EPM 2022 deployments to 2022 SU6 or later, and EPM 2024 deployments to the September 2024 (or later) update, per Ivanti's urgent advisory. Until patched, restrict network access to the EPM web console/core server, keep the EPM administrator population to a minimum since the flaw requires admin credentials, and review logs for anomalous admin activity. Given the elevated EPSS score, prioritize this patch promptly even though it is not yet on CISA KEV.
| Ivanti Endpoint Manager (EPM) | 2022 versions before 2022 SU6; 2024 versions before the September 2024 update |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
- Vendors
- ivanti
- Products
- endpoint manager
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H