HomeSecurityCISA: Adds new Ivanti EPM vulnerability to KEV List

CISA: Adds new Ivanti EPM vulnerability to KEV List

CISA has added another Ivanti vulnerability to the Catalog of Exploitable Vulnerabilities (KEV) , which could allow remote code execution on vulnerable devices with Endpoint Manager (EPM).

Ivanti EPM vulnerability CISA

Ivanti EPM is a comprehensive endpoint management solution that helps manage devices across platforms (Windows, macOS, Chrome OS, and IoT).

See also: CISA adds Ivanti vTM vulnerability to KEV List

The vulnerability is tracked as CVE-2024-29824, falls under the SQL Injection and is located in the Ivanti EPM Core server. Unauthorized attackers, within the same network, can exploit it to execute code on vulnerable systems. Ivanti patched this vulnerability in May.

Horizon3.ai security researchers published a detailed report on the CVE-2024-29824 vulnerability in June and released a proof-of-concept exploit on GitHub.

Ivanti has now updated its original security advisory to confirm the CVE-2024-29824 exploit. “We are aware of a limited number of customers who have been exploited,” the company said.

CISA has added the Ivanti vulnerability to the KEV List and is urging federal enterprises to update vulnerable devices within three weeks, specifically by October 23.

See also: Ivanti warns of new CSA vulnerability

While CISA's KEV list is primarily designed to alert federal agencies, all organizations should prioritize patching this vulnerability.

The KEV catalog is very useful for organizations around the world who want to learn about new threats and are interested in better vulnerability management and prioritization.

CISA: Adds new Ivanti EPM vulnerability to KEV List

Overall, CISA helps a lot in protecting and addressing cybersecurity threats. This organization works with various sectors, such as private businesses, state governments, and local authorities, to improve the security of digital systems.

See also: PoC exploit for critical vulnerability in Ivanti Endpoint Manager

It provides information and tools to help organizations protect their networks from cyberattacks and respond to any attacks that may occur. It also informs the public about any vulnerabilities in widely used systems and applications.

Overall, CISA's role is vital to protecting the digital infrastructure of the US and other regions.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS