๐Ÿ” CVE Alert

CVE-2024-29824

CRITICAL 9.6 โš ๏ธ CISA KEV
CVSS Score
9.6
EPSS Score
0.0%
EPSS Percentile
0th

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

Vendor ivanti
Product epm
Ecosystems
Industries
SecurityNetworking
Published May 31, 2024
Last Updated Oct 21, 2025
โš ๏ธ Actively Exploited โ€” Act Now

Get instant alerts for ivanti epm

This vulnerability is actively exploited in the wild. Set up free real-time alerts so you're first to know about threats like CVE-2024-29824.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Versions

Ivanti / EPM
2022 SU5 โ‰ค 2022 SU5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
forums.ivanti.com: https://forums.ivanti.com/s/article/Security-Advisory-May-2024 cisa.gov: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-29824