Ivanti endpoint manager是美国Ivanti公司的一款终端安全管理产品。 Ivanti endpoint manager 2024 SU7之前版本存在输入验证错误漏洞,该漏洞源于Core组件中的文件名外部控制问题,可能导致远程认证攻击者完全控制用于会话记录存储的S3存储桶的写入。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Ivanti | Endpoint Manager | 2024 SU7 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Ivanti | Endpoint Manager | 2024 SU7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18129 | 8.1 HIGH | Ivanti endpoint manager 加密问题漏洞 |
| CVE-2026-18125 | 7.5 HIGH | Ivanti endpoint manager 缓冲区错误漏洞 |
No comments yet