← Back

CVE-2024-13158

nvd nist
Published: Jan 14, 2025Modified: Aug 12, 2025

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: 3c1d8aa1-5a33-4ea4-8992-aadd6440af75 (Secondary)

Description

An unbounded resource search path in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

Affected (7)

1 product
Endpoint Manager
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Ivanti
Before 2024
Version 2022
Version 2022 su1
Version 2022 su2
Version 2022 su3
Version 2022 su4
Version 2022 su5

References (1)

Timeline

No history available yet.