CyberzSOC

Publication detail
← Back to advisories & guidance

2024-050: Multiple Vulnerabilities in Ivanti EPMM ↗ source

May 22, 2024 CERT-EU Advisory

Summary

An attacker could exploit these flaws to execute arbitrary commands on the appliance. It is strongly advised updating affected systems to the latest versions to mitigate these risks. The vulnerability CVE-2024-22026, with a CVSS score of 6.7 is a local privilege escalation vulnerability allowing an authenticated user to execute arbitrary commands with root privileges by crafting and delivering a malicious RPM package. [1,2,3] The vulnerabilities CVE-2023-46806 and CVE-2023-46807, both with a CVSS score of 6.7, are SQL Injection vulnerabilities in the web component of EPMM which allows an authenticated user with appropriate privilege to access or modify data in the underlying database. [1] It is strongly recommended to update affected devices to version 12.1.0.0 or later.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2023-46806 6.7 Medium Ivanti EPMM An SQL Injection vulnerability in a web component of EPMM versions before 12.1.0.0 allows an authenticated user with appropriate privilege to access …
CVE-2023-46807 6.7 Medium Ivanti EPMM An SQL Injection vulnerability in web component of EPMM before 12.1.0.0 allows an authenticated user with appropriate privilege to access or modify d…
CVE-2024-22026 6.7 Medium Ivanti EPMM A local privilege escalation vulnerability in EPMM before 12.1.0.0 allows an authenticated local user to bypass shell restriction and execute arbitra…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.