US government flags major Ivanti security flaw, so patch now



The US Cybersecurity and Infrastructure Security Agency (CISA) has added a known Ivanti bug to its Known Exploited Vulnerabilities (KEV) catalog, signalling that it’s being actively abused in the wild.

The bug that was just added is an SQL Injection vulnerability, found this spring in the Core server of Ivanti Endpoint Manager (EPM) 2022 SU5 and prior. It grants an unauthenticated attacker within the same network the ability to run arbitrary code. It is tracked as CVE-2024-29824, and has a severity score of 9.6 (critical).

https://cdn.mos.cms.futurecdn.net/5fz9SMYxWbv44jFVcD4vmd-1200-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img