CVE-2024-37397
largeUnauthenticated XXE in Ivanti Endpoint Manager provisioning service leaks API secrets
CVE-2024-37397 is an XML External Entity (XXE) injection flaw (CWE-611) in the provisioning web service of Ivanti Endpoint Manager (EPM), where the service parses attacker-supplied XML without properly restricting external entity resolution. A remote, unauthenticated attacker can send crafted XML to the provisioning web service to trigger external entity expansion and read sensitive data from the EPM core server. The primary impact per the advisory is disclosure of API secrets, and the CVSS 3.1 score of 8.2 (high confidentiality, low integrity, no availability impact) reflects significant data exposure. Organizations running Ivanti EPM versions before 2022 SU6, or 2024 releases before the 2024 September update, are affected. No public PoC, KEV listing, or confirmed in-the-wild exploitation is known, but the EPSS score of 59.3% (99th percentile) indicates a high probability of exploitation within the next 30 days.
What to do: Upgrade 2022-branch EPM installations to 2022 SU6 and 2024-branch installations to the 2024 September update. Until patched, restrict network access to the EPM core server's provisioning web service (e.g., firewall or WAF rules limiting it to trusted hosts) and review logs for unexpected XML requests to that service. Given the elevated EPSS score, prioritize patching internet-reachable EPM core servers first.
| Ivanti Endpoint Manager (EPM) — 2022 and earlier branches | all versions before 2022 SU6 |
| Ivanti Endpoint Manager (EPM) — 2024 branch | before the 2024 September update |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to leak API secrets.
- Vendors
- ivanti
- Products
- endpoint manager
- Weakness
- CWE-611
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N