The U.S. Cybersecurity and Infrastructure Security Agency (CISA) the Ivanti Virtual Traffic Manager authentication bypass vulnerability (CVSS score of 9.6) to its .
In May, Ivanti rolled out security patches to address multiple critical vulnerabilities in the Endpoint Manager (EPM), including CVE-2024-29824.
The vulnerability is an unspecified SQL Injection issue in Core server of Ivanti EPM 2022 SU5 and prior. An unauthenticated attacker within the same network could exploit the vulnerability to execute arbitrary code.
At the time of its disclosure, the company reported that it was not aware of attacks in the wild exploiting the vulnerability.
According to , FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend private organizations review the and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix this vulnerability by October 23, 2024.
Follow me on Twitter: and and Mastodon
(SecurityAffairs – hacking, CISA)