An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Endpoint_manager | Ivanti | * | 2024 (excluding) |
| Endpoint_manager | Ivanti | 2024 (including) | 2024 (including) |
| Endpoint_manager | Ivanti | 2024-su1 (including) | 2024-su1 (including) |
| Endpoint_manager | Ivanti | 2024-su2 (including) | 2024-su2 (including) |
| Endpoint_manager | Ivanti | 2024-su3 (including) | 2024-su3 (including) |
| Endpoint_manager | Ivanti | 2024-su3_security_release_1 (including) | 2024-su3_security_release_1 (including) |
| Endpoint_manager | Ivanti | 2024-su4 (including) | 2024-su4 (including) |
| Endpoint_manager | Ivanti | 2024-su4_sr1 (including) | 2024-su4_sr1 (including) |