Skip to content
COOEY

EXPOSURES › CVE-2024-29824

CVE-2024-29824

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-10-02 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-29824 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildransomwareunpatched

Ivanti Endpoint Manager (EPM) Core server is vulnerable to unauthenticated SQL injection enabling arbitrary code execution within the same network.

This SQL injection flaw in Ivanti's EPM Core server allows attackers to execute arbitrary code without authentication, posing a severe risk to DIB organizations relying on endpoint management tools. The vulnerability is actively exploited and linked to ransomware campaigns, making it a critical compliance failure for FedRAMP and NIST 800-171 environments. Organizations must immediately patch the Core server and audit network segmentation to prevent lateral movement.

Shame score — Active exploitation of a high-severity SQL injection in a widely deployed endpoint management product indicates a critical security oversight.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Ivanti Endpoint Manager (EPM) contains a SQL injection vulnerability in Core server that allows an unauthenticated attacker within the same network to execute arbitrary code.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Ivanti Neurons for ITSM (Formerly Service Manager)
Ivanti
Authorized
Ivanti Neurons for MDM (Formerly MobileIron)
Ivanti
Authorized