EXPOSURES › CVE-2024-29824
CVE-2024-29824
HIGH ⌖ ON CISA KEV · EXPLOITEDIvanti Endpoint Manager (EPM) Core server is vulnerable to unauthenticated SQL injection enabling arbitrary code execution within the same network.
This SQL injection flaw in Ivanti's EPM Core server allows attackers to execute arbitrary code without authentication, posing a severe risk to DIB organizations relying on endpoint management tools. The vulnerability is actively exploited and linked to ransomware campaigns, making it a critical compliance failure for FedRAMP and NIST 800-171 environments. Organizations must immediately patch the Core server and audit network segmentation to prevent lateral movement.
Shame score — Active exploitation of a high-severity SQL injection in a widely deployed endpoint management product indicates a critical security oversight.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Endpoint Manager (EPM) contains a SQL injection vulnerability in Core server that allows an unauthenticated attacker within the same network to execute arbitrary code.
| PRODUCT | STATUS |
|---|---|
| Ivanti Neurons for ITSM (Formerly Service Manager) Ivanti |
Authorized |
| Ivanti Neurons for MDM (Formerly MobileIron) Ivanti |
Authorized |