CVE-2024-34785
largeAuthenticated SQL Injection Leading to RCE in Ivanti Endpoint Manager (EPM)
CVE-2024-34785 is a SQL injection flaw (CWE-89) in Ivanti Endpoint Manager (EPM) that can be exploited remotely by an authenticated attacker holding admin-level privileges. It is triggered by attacker-controlled input processed by the EPM backend database in a request made with administrative credentials. Successful exploitation escalates from the database to arbitrary code execution on the EPM server, giving the attacker control of the management platform and, transitively, the endpoints it manages. Affected deployments are Ivanti EPM 2022 before SU6 and EPM 2024 before the September 2024 update. There is no known in-the-wild exploitation or public proof-of-concept yet, but the 25.4% EPSS score (98th percentile) signals a significant probability of exploitation within the next 30 days.
What to do: Upgrade EPM 2022 to SU6 and EPM 2024 to the September 2024 update, since the flaw is fixed in both release streams. Because exploitation requires admin privileges on the EPM console/API, inventory which accounts hold EPM administrator rights, rotate any credentials that could be compromised, and keep EPM core servers off the public internet where possible. Monitor EPM servers for anomalous database or process activity as a precaution given the elevated EPSS likelihood.
| Ivanti Endpoint Manager (EPM) 2022 | all versions prior to the 2022 SU6 release |
| Ivanti Endpoint Manager (EPM) 2024 | all versions prior to the September 2024 update |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
- Vendors
- ivanti
- Products
- endpoint manager
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H