CVE-2024-29826 is an unspecified SQL Injection vulnerability in the Core server of Ivanti Endpoint Manager (EPM) 2022 SU5 and earlier. This critical flaw allows an unauthenticated attacker on the same network to execute arbitrary code with high impact on confidentiality, integrity, and availability. While there are no public exploits or Metasploit modules, the vulnerability has garnered significant community discussion and media coverage, indicating awareness and potential for future exploitation. Organizations using affected Ivanti EPM versions should prioritize patching to mitigate this high-risk vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2022CPE matchmatch criteria | cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*:* | ||
2022CPE matchmatch criteria | cpe:2.3:a:ivanti:endpoint_manager:2022:-:*:*:*:*:*:* | ||
2022CPE matchmatch criteria | cpe:2.3:a:ivanti:endpoint_manager:2022:su1:*:*:*:*:*:* | ||
2022CPE matchmatch criteria | cpe:2.3:a:ivanti:endpoint_manager:2022:su2:*:*:*:*:*:* | ||
2022CPE matchmatch criteria | cpe:2.3:a:ivanti:endpoint_manager:2022:su3:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.