← Back to browse · API

CVE-2024-34783

Severity
CRITICAL
CVSS
9.1
EPSS
0.43356
Risk score
51.57
CISA KEV
No
PoC
No
Published
2024-09-12
Modified
2024-09-12
First seen
2026-08-07
Aliases
EUVD-2024-35049, GHSA-W8HF-8RPM-XJP2
Products
Ivanti:EPM 2022 SU6 <2022 SU6, Ivanti:EPM 2024 September Security Update <2024 September Security Update
Sources
euvd EUVD-2024-35049

Description

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

References