CVE-2024-32848
Ivanti Endpoint Manager vulnerability analysis and mitigation

Overview

An unspecified SQL injection vulnerability (CVE-2024-32848) was discovered in Ivanti Endpoint Manager (EPM) affecting versions before 2022 SU6 and the 2024 September update. The vulnerability was reported on June 5, 2024, and publicly disclosed on September 11, 2024. This security flaw specifically affects the updateAssetInfo method implementation in the Ivanti EPM software (NVD, ZDI).

Technical details

The vulnerability stems from improper validation of user-supplied strings used in SQL query construction within the updateAssetInfo method. It has been assigned a CVSS v3.1 base score of 7.2 (High) with the vector string CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H. The vulnerability is classified as CWE-89 (SQL Injection). HackerOne has additionally assessed it with a CVSS score of 9.1 (Critical) using the vector string CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H (NVD, ZDI).

Impact

If successfully exploited, this vulnerability allows an authenticated attacker with admin privileges to execute arbitrary code in the context of the service account, potentially leading to remote code execution on affected systems (ZDI).

Mitigation and workarounds

Ivanti has released security updates to address this vulnerability. Users should update to EPM 2022 SU6 or apply the 2024 September update. It's worth noting that this vulnerability was later found to have incomplete fixes, leading to the creation of CVE-2024-13162, which required additional patches in January 2025 (NVD).

Additional resources


SourceThis report was generated using AI

Related Ivanti Endpoint Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-10573 CRITICAL9.6
  • Ivanti Endpoint ManagerIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
NoYesDec 09, 2025
CVE-2025-13659HIGH8.8
  • Ivanti Endpoint ManagerIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
NoYesDec 09, 2025
CVE-2025-13661HIGH8
  • Ivanti Endpoint ManagerIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
NoNoDec 09, 2025
CVE-2025-13662HIGH7.8
  • Ivanti Endpoint ManagerIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
NoNoDec 09, 2025
CVE-2025-10573MEDIUM6.1
  • Ivanti Endpoint ManagerIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
NoNoDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management