← Back to browse · API

CVE-2024-34779

Severity
CRITICAL
CVSS
9.1
EPSS
0.24005
Risk score
44.8
CISA KEV
No
PoC
No
Published
2024-09-12
Modified
2024-09-12
First seen
2026-08-07
Aliases
EUVD-2024-35045, GHSA-G7WM-3Q7G-G3Q2
Products
Ivanti:EPM 2022 SU6 <2022 SU6, Ivanti:EPM 2024 September Security Update <2024 September Security Update
Sources
euvd EUVD-2024-35045

Description

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

References