HIGH
CVE-2024-29824
CVSS
8.8
KEV
Description
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
Summary dbcve.org
SQL injection vulnerability in the Core server component of Ivanti Endpoint Manager (EPM) 2022 SU5 and prior allows an unauthenticated attacker with network access to inject malicious SQL queries that can lead to arbitrary code execution.
Mitigation
Apply vendor-supplied patch for Ivanti EPM 2022 SU5 or upgrade to a patched version; restrict network access to the Core server to trusted entities only.
Weakness (CWE)
CWE-89
SQL Injection
EPSS Score
99.95%
Probability of exploitation in next 30 days
100th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.