CVE-2024-37397 is an External XML Entity (XXE) vulnerability in Ivanti Endpoint Manager (EPM) versions prior to 2022 SU6 or the 2024 September update. This flaw allows a remote, unauthenticated attacker to leak API secrets from the provisioning web service. With a CVSS score of 8.2 (High), it presents a significant risk due to its network-based attack vector, low attack complexity, and high confidentiality impact. While the EPSS score indicates a higher than average exploitability probability, there is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2022CPE matchmatch criteria | cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*:* | ||
2022CPE matchmatch criteria | cpe:2.3:a:ivanti:endpoint_manager:2022:-:*:*:*:*:*:* | ||
2022CPE matchmatch criteria | cpe:2.3:a:ivanti:endpoint_manager:2022:su1:*:*:*:*:*:* | ||
2022CPE matchmatch criteria | cpe:2.3:a:ivanti:endpoint_manager:2022:su2:*:*:*:*:*:* | ||
2022CPE matchmatch criteria | cpe:2.3:a:ivanti:endpoint_manager:2022:su3:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.