CVE-2024-13162 Details
Description
SQL injection in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. This CVE addresses incomplete fixes from CVE-2024-32848.
A SQL injection vulnerability has been identified in Ivanti Endpoint Manager (EPM) versions prior to the January 2024-2025 Security Update and the 2022 SU6 January-2025 Security Update. This vulnerability allows remote authenticated attackers with admin privileges to execute code remotely. The issue arises from incomplete fixes related to a previous vulnerability, CVE-2024-32848.
Users should apply the hot patches available for their respective EPM version. The hot patch for EPM 2024 can be downloaded from the Ivanti License System (ILS) and should be applied to the core server and remote consoles. For EPM 2022 SU6, a similar hot patch is also available through ILS. After applying the patch, the core server should be rebooted.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6 | ivanti | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | ivanti |
Affected Products
| Product | Versions |
|---|---|
| ivanti endpoint manager | < 2022 2022 - 2022 su1 2022 su2 2022 su3 2022 su4 2022 su5 2024 - |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ivanti |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 11, 2025 | Initial Analysis | [email protected] |
| Jan 14, 2025 | New CVE Received | ivanti |