CyberRota Analysis
AI-GeneratedIvanti Endpoint Manager versions prior to 2024 SU7 are vulnerable to an external control of a filename, enabling remote authenticated attackers to gain full write access to S3 buckets used for session recording storage. This vulnerability poses a significant risk as it could lead to unauthorized data manipulation or exposure. Organizations using affected versions should prioritize patching to mitigate potential data breaches and maintain security integrity.
Original NVD Description
External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage.