← Vulnerability feed

Vulnerability record · CVE-2024-13162 · published 14 January 2025

CVE-2024-13162: Ivanti EPM SQL injection leads to remote code execution

Ivanti · Endpoint Manager

Ivanti Endpoint Manager contains a SQL injection flaw that lets a remote authenticated attacker with admin privileges achieve remote code execution. It is an incomplete fix for CVE-2024-32848, so the earlier patch does not fully close the issue. Because the affected product is an endpoint management platform, successful exploitation can compromise the management server and the endpoints it controls.

7.2 CVSS 3.1 High EPSS 64% · top 0.8% CWE-89 · SQL injection
7.2CVSS 3.1 base score
64%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

SQL injection in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. This CVE addresses incomplete fixes from CVE-2024-32848.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityThe flaw yields remote code execution on a central endpoint management server, but exploitation requires an existing admin account, which lowers the immediate risk compared with unauthenticated flaws.

What it is

Ivanti Endpoint Manager contains a SQL injection flaw that lets a remote authenticated attacker with admin privileges achieve remote code execution. It is an incomplete fix for CVE-2024-32848, so the earlier patch does not fully close the issue. Because the affected product is an endpoint management platform, successful exploitation can compromise the management server and the endpoints it controls.

Impact

An attacker with admin privileges gains remote code execution on the EPM server, allowing full control of that host and potentially the managed endpoint fleet. The CVSS vector rates confidentiality, integrity and availability impact as high.

Attack surface

Reachable over the network (AV:N) with no user interaction (UI:N), but it requires high privileges (PR:H), meaning the attacker must already hold an admin account on the EPM instance. No other preconditions are described in the record.

Exploitation

CISA KEV does not list this CVE, and the only reference is the vendor advisory, so there is no public evidence of active exploitation in this record. EPSS is high at 0.64176 (99.19th percentile), indicating elevated predicted likelihood of exploitation.

What to do

  • Apply the Ivanti EPM January-2025 Security Update for EPM 2024 or the 2022 SU6 January-2025 Security Update, which addresses the incomplete fix from CVE-2024-32848.
  • Restrict and audit admin-level accounts on EPM; the flaw requires admin privileges, so reducing and monitoring privileged access limits exposure.
  • Limit network access to the EPM server to trusted management networks rather than exposing it broadly.
  • Review and rotate credentials for EPM admin accounts if compromise is suspected, since RCE on the server can expose stored secrets.

Detection

  • Monitor EPM server and database logs for anomalous SQL statements or errors consistent with injection attempts.
  • Alert on unexpected child processes or command execution spawned by the EPM application or its database service.
  • Audit EPM admin account activity for unusual logins, queries or configuration changes.
  • Watch for outbound connections from the EPM server to unfamiliar hosts that could indicate post-exploitation activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-13162 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2024-29824Ivanti Endpoint Manager Core Server SQL Injection Enables RCEIvanti Endpoint Manager 2022 SU5 and earlier contains an unspecified SQL injection in the Core server. An unauthenticated attacker on the same networ…KEVEPSS 100%analysed7.5CVE-2026-1603Ivanti Endpoint Manager authentication bypass leaks stored credentialsIvanti Endpoint Manager before 2024 SU5 contains an authentication bypass (CWE-288/CWE-306) that lets a remote, unauthenticated attacker reach a func…KEVEPSS 88%analysed7.5CVE-2024-13159Ivanti EPM absolute path traversal leaks sensitive filesIvanti Endpoint Manager (EPM) contains an absolute path traversal flaw (CWE-36) that lets a remote attacker read files outside the intended directory…KEVEPSS 100%analysed7.5CVE-2024-13160Ivanti Endpoint Manager absolute path traversal information leakIvanti Endpoint Manager (EPM) contains an absolute path traversal flaw (CWE-36) that allows a remote, unauthenticated attacker to read files outside …KEVEPSS 91%analysed7.5CVE-2024-13161Ivanti Endpoint Manager absolute path traversal leaks sensitive filesIvanti Endpoint Manager (EPM) contains an absolute path traversal flaw (CWE-36) that lets a remote attacker read files outside the intended directory…KEVEPSS 90%analysed9.9CVE-2020-13774Ivanti endpoint manager unrestricted file upload vulnerabilityAn unrestricted file-upload issue in EditLaunchPadDialog.aspx in Ivanti Endpoint Manager 2019.1 and 2020.1 allows an authenticated attacker to gain r…EPSS 5.0%9.8CVE-2024-50330Ivanti endpoint manager sql injection vulnerabilitySQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated at…EPSS 40%9.8CVE-2024-29847Ivanti EPM agent portal deserialization allows unauthenticated RCEThe agent portal in Ivanti Endpoint Manager (EPM) deserializes untrusted data, allowing a remote unauthenticated attacker to execute code. The flaw a…EPSS 53%analysed

Source: NIST National Vulnerability Database (record CVE-2024-13162), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.