ZeroHour

CVE-2024-37397

large

Unauthenticated XXE in Ivanti Endpoint Manager provisioning service leaks API secrets

CVSS 3.1
8.2 high
EPSS
59%p99
Published
()
Modified
AI analysis

CVE-2024-37397 is an XML External Entity (XXE) injection flaw (CWE-611) in the provisioning web service of Ivanti Endpoint Manager (EPM), where the service parses attacker-supplied XML without properly restricting external entity resolution. A remote, unauthenticated attacker can send crafted XML to the provisioning web service to trigger external entity expansion and read sensitive data from the EPM core server. The primary impact per the advisory is disclosure of API secrets, and the CVSS 3.1 score of 8.2 (high confidentiality, low integrity, no availability impact) reflects significant data exposure. Organizations running Ivanti EPM versions before 2022 SU6, or 2024 releases before the 2024 September update, are affected. No public PoC, KEV listing, or confirmed in-the-wild exploitation is known, but the EPSS score of 59.3% (99th percentile) indicates a high probability of exploitation within the next 30 days.

What to do: Upgrade 2022-branch EPM installations to 2022 SU6 and 2024-branch installations to the 2024 September update. Until patched, restrict network access to the EPM core server's provisioning web service (e.g., firewall or WAF rules limiting it to trusted hosts) and review logs for unexpected XML requests to that service. Given the elevated EPSS score, prioritize patching internet-reachable EPM core servers first.

Affected
Ivanti Endpoint Manager (EPM) — 2022 and earlier branchesall versions before 2022 SU6
Ivanti Endpoint Manager (EPM) — 2024 branchbefore the 2024 September update
Estimated exposure
large≈tens of thousands of on-premises enterprise deployments (order-of-magnitude estimate) — Ivanti EPM (formerly LANDESK) is a long-established, widely deployed on-premises enterprise endpoint-management platform with a customer base in the tens of thousands, though only a subset of deployments expose the provisioning web service…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to leak API secrets.

Vendors
ivanti
Products
endpoint manager
Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

In the news