← Back to browse · API

CVE-2024-32845

Severity
CRITICAL
CVSS
9.1
EPSS
0.24005
Risk score
44.8
CISA KEV
No
PoC
No
Published
2024-09-12
Modified
2024-09-12
First seen
2026-08-07
Aliases
EUVD-2024-30631, GHSA-F53W-FW63-QJPW
Products
Ivanti:EPM 2022 SU6 <2022 SU6, Ivanti:EPM 2024 September Security Update <2024 September Security Update
Sources
euvd EUVD-2024-30631

Description

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

References