CVE-2024-29824Disclosure(ivanti / endpoint_manager)

LOWCVSS 8.8 · HIGHCISA KEV

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

0.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-10-23. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • endpoint_manager

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-03-30); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
endpoint_manager

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-30: 1Mentions · 2026-03-31: 1Technical Details · 2026-03-30: 1Technical Details · 2026-03-31: 103-3003-31
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Patrick Roland@DeusLogica
    Disclosure

    🔴 EPSS 94.0% | Almost certainly exploitation | medium confidence CVE-2024-29824 (EPSS 94.00%) Ivanti EPM Core server SQL Injection allows unauthenticated attacker within same network segment to execute arbitrary SQL commands. Highest risk of all CVEs by exploitation likelihood Source: http://FIRST.org EPSS | Reliability: B Link: https://nvd.nist.gov/vuln/detail/CVE-2024-29824 #EPSS #threatintel #CVE #cybersecurity

    Post summary

    The post discloses that CVE‑2024‑29824 is a SQL injection vulnerability in Ivanti EPM Core Server, enabling unauthenticated attackers on the same network segment to run arbitrary SQL commands.

    1000068
    311 followersView on X
  • Patrick Roland@DeusLogica
    Disclosure

    Timestamp: 2026-03-30T11:11:47.242081 Type: HIGH_EPSS Severity: CRITICAL Confidence: MEDIUM Source Reliability: B Title: CVE-2024-29824 (EPSS 94.00%) ## Draft Post 🔴 EPSS 94.0% | Almost certainly exploitation | medium confidence CVE-2024-29824 (EPSS 94.00%) An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network Highest risk of all CVEs by exploitation likelihood Source: http://FIRST.org EPSS | Reliability: B Link: https://nvd.nist.gov/vuln/detail/CVE-2024-29824 #EPSS #threatintel #CVE #cybersecurity ## CTI Metadata - Confidence Level: MEDIUM - Source Reliability: B - Calibrated Language: medium confidence

    Post summary

    This post announces CVE-2024-29824, an SQL injection in Ivanti EPM, highlighting high exploitation likelihood but providing no evidence of active attacks, exploits, or patches.

    1000056
    307 followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
Appivantiendpoint_manager---
Appivantiendpoint_manager2022--
Appivantiendpoint_manager2022--
Appivantiendpoint_manager2022--
Appivantiendpoint_manager2022--
Appivantiendpoint_manager2022--
Appivantiendpoint_manager2022--

Explore more