Junglewise Threat Intelligence

CVE-2024-29824: Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability

CVE-2024-29824 · Severity: critical · CVSS 9.6 · Exploited in the wild · Published 2024-10-02

Technologies: Ivanti Endpoint Manager (EPM). Vendors: Ivanti.

Executive brief

An unspecified SQL injection vulnerability in the Core server of Ivanti Endpoint Manager (EPM) allows an unauthenticated attacker on the same network to execute arbitrary code. The vulnerability is confirmed to be exploited in the wild.

Affected products

  • Ivanti Endpoint Manager (EPM) 2022 SU5 and prior

Timeline

  • 2024-05-31: disclosed: NVD Published Date
  • 2024-10-02: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-10-23: other: CISA KEV remediation due date

Related threats