HIGH

CVE-2024-29824

Ivanti Endpoint Manager 2024-05-31 CVSS v3.1
CVSS
8.8
KEV

Description

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

Summary dbcve.org

SQL injection vulnerability in the Core server component of Ivanti Endpoint Manager (EPM) 2022 SU5 and prior allows an unauthenticated attacker with network access to inject malicious SQL queries that can lead to arbitrary code execution.

Mitigation

Apply vendor-supplied patch for Ivanti EPM 2022 SU5 or upgrade to a patched version; restrict network access to the Core server to trusted entities only.

Weakness (CWE)

CWE-89 SQL Injection

EPSS Score

99.95%
Probability of exploitation in next 30 days
100th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE