Affected Systems
Ivanti Endpoint Manager (EPM). Specific affected versions not disclosed in available advisory. CVE identifiers not yet assigned or published.
Exploitation Status
Exploitation status unknown. No CVE identifiers published yet. No public PoC or active exploitation confirmed in available sources.
Business Impact
Organizations using Ivanti EPM for endpoint management face potential compromise of managed endpoints and administrative infrastructure. Severity rated as high by CERT.BE, suggesting significant risk. Lack of public CVE details limits ability to assess specific attack vectors and scope. Immediate patching recommended by national CERT indicates vendor patches are available.
Urgency
🔴 Immediate
Recommended Actions
- Identify all Ivanti Endpoint Manager (EPM) instances in your environment immediately
- Check Ivanti security advisory portal for specific patch releases and affected version details
- Apply vendor-supplied patches to all Ivanti EPM servers and components as soon as possible
- Monitor Ivanti EPM logs for suspicious authentication attempts or unusual administrative activity during patching window
- Subscribe to Ivanti security bulletins and CERT.BE advisories for CVE assignment and additional technical details
