CyberzSOC

Publication detail
← Back to advisories & guidance

2024-002: Critical Vulnerability in Ivanti Endpoint Management Software ↗ source

January 8, 2024 CERT-EU Advisory

Summary

This vulnerability, tracked as CVE-2023-39336 (CVSS score : 9.6), allows unauthenticated attackers to hijack enrolled devices or the core server. Ivanti EPM is used to manage client devices across various platforms, including Windows, macOS, Chrome OS, and IoT operating systems. The vulnerability affects all supported versions of Ivanti EPM and has been resolved in version 2022 Service Update 5. The editor also states that no evidence of active exploitation was currently found. The vulnerability allows attackers with access to a target’s internal network to exploit the flaw in low-complexity attacks without requiring privileges or user interaction.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2023-39336 9.6 Critical Ivanti Endpoint Manager An unspecified SQL Injection vulnerability in Ivanti Endpoint Manager released prior to 2022 SU 5 allows an attacker with access to the internal net…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.