LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-29824: Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Oct 2, 2024
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Oct 23, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-29824 to its Known Exploited Vulnerabilities catalog on Oct 2, 2024, with a federal patch deadline of Oct 23, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Ivanti Endpoint Manager (EPM) contains a SQL injection vulnerability in Core server that allows an unauthenticated attacker within the same network to execute arbitrary code.

CVE-2024-29824 is a SQL injection flaw in the Core server component of Ivanti Endpoint Manager (EPM). An unauthenticated attacker who can reach the Core server from the same network can abuse it to execute arbitrary code. Because EPM is used to manage and control large numbers of endpoints, successful exploitation can give an attacker a foothold that extends well beyond the management server itself.

Organizations running EPM should treat this as a high-priority issue for any Core server that is reachable by untrusted or semi-trusted hosts on the internal network. Confirm all version and patch details against the official Ivanti advisory before acting.

How it works

The vulnerability is classified as CWE-89 (SQL Injection). In this class of flaw, user-controlled input is incorporated into a database query without proper sanitization or parameterization. An attacker crafts input that alters the intended SQL statement, allowing them to read, modify, or execute commands through the database engine.

According to the CISA summary, the injection point resides in the Ivanti EPM Core server and does not require authentication. An attacker already positioned on the same network can send specially formed requests that trigger the injection and ultimately achieve arbitrary code execution on the server. Exact request formats, parameters, and payload construction are not detailed in the public summary; defenders must rely on the vendor advisory for any technical indicators of compromise or proof-of-concept information.

Am I affected? How to find it in your systems

Ivanti Endpoint Manager is typically deployed in enterprise environments as a central console for software distribution, patching, inventory, and remote control of Windows and other endpoints. The Core server is the central component that stores configuration data and issues management commands.

Public detail on exact vulnerable builds is limited to the vendor advisory; treat any unpatched Core server as potentially affected until confirmed otherwise.

How to remediate

The primary remediation is to apply the vendor-supplied update for Ivanti Endpoint Manager that addresses CVE-2024-29824. Follow the installation and verification steps published by Ivanti exactly.

CISA’s required action is to apply mitigations per vendor instructions or to discontinue use of the product if mitigations are unavailable. Confirm the latest guidance directly from Ivanti.

If you can't patch immediately

Until the official update can be applied, reduce exposure with compensating controls that limit network access and increase detection.

These measures lower risk but do not eliminate it; plan to patch as soon as operationally feasible.

If your data may have been exposed

Actively exploited management-server vulnerabilities frequently lead to broader network compromise and data exposure. If you have reason to believe an attacker reached your EPM Core server, assume credentials, endpoint inventories, and any stored configuration data may have been accessed. Rotate administrative credentials, review endpoint integrity, and examine network logs for lateral movement. As an additional check, you can run a free exposure scan of your email addresses against known breach data sets to determine whether related accounts appear in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedIvanti · Endpoint Manager (EPM)
WeaknessCWE-89
Added to CISA KEVOct 2, 2024
Federal patch deadlineOct 23, 2024
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities