← Back to browse · API

CVE-2024-32840

Severity
CRITICAL
CVSS
9.1
EPSS
0.25389
Risk score
45.29
CISA KEV
No
PoC
No
Published
2024-09-12
Modified
2024-09-12
First seen
2026-08-07
Aliases
EUVD-2024-30626, GHSA-PCXJ-W6PV-X9C5
Products
Ivanti:EPM 2022 SU6 <2022 SU6, Ivanti:EPM 2024 September Security Update <2024 September Security Update
Sources
euvd EUVD-2024-30626

Description

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

References