Critical SQL Injection flaws impact Ivanti Endpoint Manager (EPM)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-29825 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code. NVD description · AI analysis pending | 8.8 group max | 100% |
| — | ||
| CVE-2024-29824 | Unauthenticated SQL Injection to RCE in Ivanti Endpoint Manager (EPM) Core Server CVE-2024-29824 is a SQL injection flaw (CWE-89) in the Core server component of Ivanti Endpoint Manager (EPM), Ivanti's on-premises endpoint management platform. An unauthenticated attacker who can reach the EPM Core server over the network can send crafted input that is passed unsafely to the underlying database, and the flaw ultimately permits execution of arbitrary code on the server. Successful exploitation gives an attacker control of the EPM Core server, which manages an organization's endpoint fleet, typically yielding broad enterprise-level privileges useful for lateral movement; ransomware use has not been confirmed. Any organization running an affected EPM Core server is exposed, though because the attack requires access to the same network, the primary risk is from attackers already inside the network or on compromised managed endpoints rather than direct internet-facing attacks. The vulnerability was added to CISA's KEV catalog on 2024-10-02, confirming exploitation in the wild, and EPSS assigns it a 100% probability of exploitation within 30 days (100th percentile); a CVSS score is not yet available and no public proof-of-concept is known. Do: Apply Ivanti's patched service update for your EPM release immediately per the vendor's instructions, prioritizing any Core server reachable from user or untrusted network segments; the KEV listing gives federal agencies a mandatory remediation deadline. As interim mitigation, restrict network access to the EPM Core server's services to management networks and administrators, and hunt for anomalous database activity or unexpected process launches on Core servers. | 8.8 | 100% | KEV |
| largetens of thousands of enterprise deployments (order of ~10,000-100,000 EPM Core servers; exact install base unpublished) |
Full article456 words · extracted from securityaffairs.com · click to collapse

Ivanti addressed multiple flaws in the Endpoint Manager (EPM), including remote code execution vulnerabilities.
Ivanti this week rolled out security patches to address multiple critical vulnerabilities in the Endpoint Manager (EPM). A remote attacker can exploit the flaws to gain code execution under certain conditions.
Below is the list of the addressed vulnerabilities:
| CVE | Description | CVSS | Vector |
| CVE-2024-29822 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code. | 9.6 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| CVE-2024-29823 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code. | 9.6 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| CVE-2024-29824 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code. | 9.6 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| CVE-2024-29825 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code. | 9.6 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| CVE-2024-29826 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code. | 9.6 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| CVE-2024-29827 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code. | 9.6 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| CVE-2024-29828 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code. | 8.4 | CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| CVE-2024-29829 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code. | 8.4 | CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| CVE-2024-29830 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code. | 8.4 | CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| CVE-2024-29846 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code. | 8.4 | CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
The vulnerabilities impact 2022 SU5 and earlier versions.
Six out of 10 vulnerabilities (CVE-2024-29822, CVE-2024-29823, CVE-2024-29824, CVE-2024-29825, CVE-2024-29826, CVE-2024-29827) have been rated critical (CVSS score 9.6).
The flaws are SQL injection issues, an unauthenticated attacker within the same network can exploit these vulnerabilities to execute arbitrary code.
The company is not aware of attacks in the wild exploiting these vulnerabilities.
“We are not aware of any customers being exploited by this vulnerability at the time of disclosure.” reads the advisory.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Ivanti Endpoint Manager)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/163587/security/ivanti-endpoint-manager-critical-sql-injection.html