#VU100539 Path traversal in Endpoint Manager - CVE-2024-34787

 

#VU100539 Path traversal in Endpoint Manager - CVE-2024-34787

Published: November 15, 2024 / Updated: November 18, 2024


Vulnerability identifier: #VU100539
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2024-34787
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Endpoint Manager
Software vendor:
Ivanti

Description

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can trick the victim into uploading a specially crafted file and overwrite arbitrary files on the system.

Successful exploitation of the vulnerability may allow an attacker to compromise the affected system.


Remediation

Install update from vendor's website.

External links