High severity8.8CISA KEVNVD Advisory· Published May 31, 2024· Updated Jun 17, 2026
CVE-2024-29824
CVE-2024-29824
Description
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
Affected products
9cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*:*range: <2022
- cpe:2.3:a:ivanti:endpoint_manager:2022:-:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2022:su1:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2022:su2:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2022:su3:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2022:su4:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2022:su5:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- forums.ivanti.com/s/article/Security-Advisory-May-2024nvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.