« Volver al listado

CVE-2024-13172

Estado: AnalizadaAlta (7.8)—

Improper signature verification in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vector CVSS con AV:L y UI:R indica ejecución en cliente (T1203). La vulnerabilidad de verificación de firma (CWE-347) permite ejecución de código remoto tras interacción del usuario (abrir archivo malformado). Impacto: ejecución de comandos y bypass de validación de código.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-13172",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-13172",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-01-24T04:55:52.576505Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "3c1d8aa1-5a33-4ea4-8992-aadd6440af75",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "3c1d8aa1-5a33-4ea4-8992-aadd6440af75",
      "affectedData": [
        {
          "vendor": "Ivanti",
          "product": "Endpoint Manager",
          "versions": [
            {
              "status": "unaffected",
              "version": "2024 January-2025 Security Update",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "2022 SU6 January-2025 Security Update",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-01-14T18:15:29.110",
  "references": [
    {
      "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "3c1d8aa1-5a33-4ea4-8992-aadd6440af75"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "3c1d8aa1-5a33-4ea4-8992-aadd6440af75",
      "description": [
        {
          "lang": "en",
          "value": "CWE-347"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper signature verification in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required."
    },
    {
      "lang": "es",
      "value": "La verificación de firmas incorrecta en Ivanti EPM antes de la actualización de seguridad de enero de 2024 a enero de 2025 y la actualización de seguridad de enero de 2022 SU6 a enero de 2025 permite que un atacante remoto no autenticado logre la ejecución remota de código. Se requiere la interacción del usuario local."
    }
  ],
  "lastModified": "2026-06-17T07:01:22.610",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ivanti:endpoint_manager:*:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "11BA6FEC-4862-4799-B8A1-9CEF9FE1B147",
              "versionEndExcluding": "2022"
            },
            {
              "criteria": "cpe:2.3:a:ivanti:endpoint_manager:2022:su1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E57E12B5-B789-450C-9476-6C4C151E6993"
            },
            {
              "criteria": "cpe:2.3:a:ivanti:endpoint_manager:2022:su2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E47C65B3-56DD-4D65-8B4B-6AFFE28E94F2"
            },
            {
              "criteria": "cpe:2.3:a:ivanti:endpoint_manager:2022:su3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "10D6EAB7-B14B-45E9-92B9-4FADFBBB08AF"
            },
            {
              "criteria": "cpe:2.3:a:ivanti:endpoint_manager:2022:su4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1877FB55-76BA-4714-ABB8-47258132F537"
            },
            {
              "criteria": "cpe:2.3:a:ivanti:endpoint_manager:2022:su5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4F9E8D45-5F12-4D45-A74E-C314FA3618A3"
            },
            {
              "criteria": "cpe:2.3:a:ivanti:endpoint_manager:2024:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6C7283FE-C10A-4E37-B004-15FB0CAC49A5"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "3c1d8aa1-5a33-4ea4-8992-aadd6440af75"
}