CVE-2024-8191
largeSQL Injection to RCE in Ivanti Endpoint Manager Management Console
Ivanti Endpoint Manager (EPM) contains an unauthenticated SQL injection flaw (CWE-89) in its management console that allows a remote attacker to achieve remote code execution on the EPM core server. The flaw is reachable over the network with no authentication and no user interaction, so anyone who can reach the console — including via the internet where it is exposed — can trigger it. Successful exploitation yields full code execution with high confidentiality, integrity, and availability impact, consistent with the critical 9.8 CVSS score. Organizations running EPM before 2022 SU6, or EPM 2024 before the September 2024 update, are affected. No public proof-of-concept or confirmed in-the-wild exploitation is known (not in CISA KEV), but the 20.3% EPSS score (97th percentile) points to an elevated probability of exploitation within 30 days.
What to do: Upgrade EPM to 2022 SU6, or apply the September 2024 update if running EPM 2024. Until patched, remove internet exposure of the EPM management console or restrict it to trusted management networks/VPN. With no public PoC available, prioritize patching and exposure reduction while monitoring the console for anomalous requests.
| Ivanti Endpoint Manager (EPM) management console | before 2022 SU6; 2024 before the September 2024 update (fixed in 2022 SU6 and the 2024 September update) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.
- Vendors
- ivanti
- Products
- endpoint manager
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H