HTTP: Ivanti Endpoint Manager MP_QueryDetail SQL Injection

This signature detects attempts to exploit a known vulnerability against Ivanti. A successful attack can lead to command injection and arbitrary code execution.

Extended Description

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

Affected Products

Ivanti endpoint_manager

Short Name
HTTP:SQL:INJ:IVANTI-MGR-MP-QRY
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2024-34781 Endpoint Injection Ivanti MP_QueryDetail Manager SQL
Release Date
06/11/2025
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3816
False Positive
Unknown
Vendors

Ivanti

Found a potential security threat?