ZeroHour

CVE-2024-8191

large

SQL Injection to RCE in Ivanti Endpoint Manager Management Console

CVSS 3.1
9.8 critical
EPSS
20%p97
Published
()
Modified
AI analysis

Ivanti Endpoint Manager (EPM) contains an unauthenticated SQL injection flaw (CWE-89) in its management console that allows a remote attacker to achieve remote code execution on the EPM core server. The flaw is reachable over the network with no authentication and no user interaction, so anyone who can reach the console — including via the internet where it is exposed — can trigger it. Successful exploitation yields full code execution with high confidentiality, integrity, and availability impact, consistent with the critical 9.8 CVSS score. Organizations running EPM before 2022 SU6, or EPM 2024 before the September 2024 update, are affected. No public proof-of-concept or confirmed in-the-wild exploitation is known (not in CISA KEV), but the 20.3% EPSS score (97th percentile) points to an elevated probability of exploitation within 30 days.

What to do: Upgrade EPM to 2022 SU6, or apply the September 2024 update if running EPM 2024. Until patched, remove internet exposure of the EPM management console or restrict it to trusted management networks/VPN. With no public PoC available, prioritize patching and exposure reduction while monitoring the console for anomalous requests.

Affected
Ivanti Endpoint Manager (EPM) management consolebefore 2022 SU6; 2024 before the September 2024 update (fixed in 2022 SU6 and the 2024 September update)
Estimated exposure
large≈ tens of thousands of EPM core-server deployments (each typically managing hundreds to thousands of endpoints), with public internet scans generally showing… — EPM (formerly LANDESK) is a long-established on-prem enterprise endpoint-management platform deployed across a large mid-market and enterprise base, but the vulnerable component is the management console, of which internet scans typically…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.

Vendors
ivanti
Products
endpoint manager
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news