>> All posts

CVE-2024-29824: Ivanti Endpoint Manager SQL injection to code execution, in CISA KEV

The short version: Ivanti Endpoint Manager (EPM) — the platform that manages and patches your fleet of endpoints — has a SQL injection flaw in its core server (CVE-2024-29824) that lets an unauthenticated attacker on the same network execute arbitrary commands, typically by turning the database into a command shell. It's in CISA's KEV catalog. If you run EPM 2022 SU5 or earlier, patch it. Steady hands, but move.

At a glance

FactDetail
Our severity takeCritical — in practice (see below)
CVSS v3.1 (NVD)8.8 — High · AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS (Ivanti, CNA)9.6 — Critical (scored with scope changed)
EPSS99.95% · 99.97th percentile (2026-07-17)
In CISA KEV?Yes — remediate by 2024-10-23 (added 2024-10-02)
Known exploited?Yes — KEV-listed; public proof-of-concept exists
Vulnerability typeCWE-89 SQL injection → arbitrary command execution on the core server
Requires authenticated session?No — pre-authentication (attacker must be on the same network)
AffectedIvanti EPM 2022 SU5 and prior (core server)
Fixed inIvanti EPM 2022 SU5 security hot patch (May 2024) and later

What you need to know

CVE-2024-29824 is an SQL injection in a specific endpoint of the EPM core server. Because the injected SQL can enable and drive the database's command-execution features, a successful attack doesn't stop at reading data — it reaches arbitrary command execution on the server itself.

Two details set the practical severity:

  • It's the management server. EPM exists to reach and control your endpoints. Code execution on that server sits upstream of a large part of your estate.
  • It's pre-authentication, but network-adjacent. NVD scores the attack vector as adjacent (AV:A) — the attacker needs to be on the same network as the EPM server, not reaching it from anywhere on the internet. That's what separates our High take from a reflexive Critical: the flaw is severe, but its reach depends on the attacker first being on your network.

How serious we see it

Critical — in practice.

NVD scores it 8.8 and Ivanti 9.6; the gap is the classic scope question, and the honest middle is that this is a serious, KEV-listed flaw whose blast radius is tempered by the adjacent-network requirement. Where an EPM core server is not internet-isolated, treat it as urgent. The bounded, reassuring part: it affects specific EPM builds, the fix is published, and you can determine quickly whether you run an affected version.

Recommendations

Straight from Ivanti's advisory and CISA:

  1. Patch now. Apply the May 2024 security hot patch for EPM 2022 SU5 (or move to a later fixed build).
  2. Restrict access. Until patched, limit reach to the EPM core server to trusted management networks only.
  3. Hunt. Review the EPM server and its database host for signs of command execution and unexpected child processes.
  4. If compromised, respond. Rebuild the affected server and rotate credentials and service-account secrets it holds.
  5. Confirm your exposure first. Verify whether you run EPM 2022 SU5 or earlier, and whether the core server is reachable beyond a trusted network.

How BreachRisk sees it

BreachRisk works from the outside in. Where an Ivanti EPM interface is exposed, BreachRisk discovers it, fingerprints the product and version, and flags exposure tied to KEV-listed vulnerabilities like this one — pushed to the top of your results because it's in KEV. We detect and flag the exposed, affected version; we don't exploit it.

That continuous, attacker's-eye view is the point: when a management platform picks up a KEV entry, the exposed server is already mapped, so you go straight to patch-and-verify.

References

See your cyber risk, proven.