Impact
An out-of-bounds read in the Agent component of Ivanti Endpoint Manager can be triggered by a remote, unauthenticated attacker, causing the agent service to crash. The flaw does not provide direct code execution; instead, it leads to a loss of availability for the protected endpoint.
Affected Systems
Ivanti Endpoint Manager, specifically versions released before 2024 SU7. Any deployment using an Agent that has not been upgraded to at least the 2024 SU7 release is susceptible.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. No EPSS score is available, so current exploitation likelihood is unknown. The vulnerability is not listed in the CISA KEV catalog. Attackers need only remote communication with the agent service, making it a likely remote threat vector that can induce service downtime without additional privileges.
OpenCVE Enrichment