Improper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary code. User Interaction is required.
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Endpoint_manager | Ivanti | * | 2024 (excluding) |
| Endpoint_manager | Ivanti | 2024 (including) | 2024 (including) |
| Endpoint_manager | Ivanti | 2024-su1 (including) | 2024-su1 (including) |
| Endpoint_manager | Ivanti | 2024-su2 (including) | 2024-su2 (including) |
| Endpoint_manager | Ivanti | 2024-su3 (including) | 2024-su3 (including) |
| Endpoint_manager | Ivanti | 2024-su3_security_release_1 (including) | 2024-su3_security_release_1 (including) |
| Endpoint_manager | Ivanti | 2024-su4 (including) | 2024-su4 (including) |