HTTP: Ivanti Endpoint Manager ETask WasPreviouslyMapped SQL Injection

This signature detects attempts to exploit a known vulnerability against Ivanti. A successful attack can lead to command injection and arbitrary code execution.

Extended Description

SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.

Affected Products

Ivanti endpoint_manager

Short Name
HTTP:SQL:INJ:IVANTI-ENDPNT-ETSK
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2024-8191 ETask Endpoint Injection Ivanti Manager SQL WasPreviouslyMapped
Release Date
12/11/2024
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3779
False Positive
Unknown
Vendors

Ivanti

Found a potential security threat?