← Vulnerability feed

Vulnerability record · CVE-2024-29823 · published 31 May 2024

CVE-2024-29823: Ivanti Endpoint Manager Core Server SQL Injection Allows Unauthenticated RCE

Ivanti · Endpoint Manager

Ivanti Endpoint Manager 2022 SU5 and earlier contain an unspecified SQL injection in the Core server. An unauthenticated attacker on the same network can exploit it to execute arbitrary code. The flaw is high severity and trivially reachable from an adjacent network position.

8.8 CVSS 3.1 High EPSS 100% · top 0.1% CWE-89 · SQL injection
8.8CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

critical priorityUnauthenticated adjacent-network code execution in a management server with an EPSS score near 1.0 makes this an urgent patch-first issue.

What it is

Ivanti Endpoint Manager 2022 SU5 and earlier contain an unspecified SQL injection in the Core server. An unauthenticated attacker on the same network can exploit it to execute arbitrary code. The flaw is high severity and trivially reachable from an adjacent network position.

Impact

Successful exploitation gives the attacker arbitrary code execution on the Core server, likely with the privileges of the service. That can lead to full compromise of the EPM management plane and any managed endpoints.

Attack surface

The vulnerability is in the Core server and is reachable over an adjacent network (AV:A) with no authentication (PR:N) and no user interaction (UI:N). An attacker only needs network access to the EPM Core server, not credentials.

Exploitation

The record shows no CISA KEV listing and no public exploit references, but EPSS is 0.9986 (99.9th percentile), indicating a very high predicted likelihood of exploitation in the next 30 days.

What to do

  • Apply the Ivanti security advisory May 2024 update for Endpoint Manager immediately; upgrade beyond 2022 SU5.
  • Restrict network access to the EPM Core server to trusted management hosts and segments; do not expose it broadly.
  • Segment EPM infrastructure from general user networks to limit adjacent-network attack paths.
  • Monitor Ivanti advisories for follow-up patches and interim guidance.
  • If patching is delayed, consider temporary network-level filtering of untrusted traffic to the Core server.

Detection

  • Monitor EPM Core server logs for anomalous SQL errors or unexpected database queries.
  • Alert on unusual outbound connections or process creation from the EPM Core server service account.
  • Hunt for signs of SQL injection attempts in network traffic to the Core server, such as malformed or unexpected query strings.
  • Review EPM server logs for authentication bypass or unexpected administrative actions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-29823 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2024-29824Ivanti Endpoint Manager Core Server SQL Injection Enables RCEIvanti Endpoint Manager 2022 SU5 and earlier contains an unspecified SQL injection in the Core server. An unauthenticated attacker on the same networ…KEVEPSS 100%analysed7.5CVE-2026-1603Ivanti Endpoint Manager authentication bypass leaks stored credentialsIvanti Endpoint Manager before 2024 SU5 contains an authentication bypass (CWE-288/CWE-306) that lets a remote, unauthenticated attacker reach a func…KEVEPSS 88%analysed7.5CVE-2024-13159Ivanti EPM absolute path traversal leaks sensitive filesIvanti Endpoint Manager (EPM) contains an absolute path traversal flaw (CWE-36) that lets a remote attacker read files outside the intended directory…KEVEPSS 100%analysed7.5CVE-2024-13160Ivanti Endpoint Manager absolute path traversal information leakIvanti Endpoint Manager (EPM) contains an absolute path traversal flaw (CWE-36) that allows a remote, unauthenticated attacker to read files outside …KEVEPSS 91%analysed7.5CVE-2024-13161Ivanti Endpoint Manager absolute path traversal leaks sensitive filesIvanti Endpoint Manager (EPM) contains an absolute path traversal flaw (CWE-36) that lets a remote attacker read files outside the intended directory…KEVEPSS 90%analysed9.9CVE-2020-13774Ivanti endpoint manager unrestricted file upload vulnerabilityAn unrestricted file-upload issue in EditLaunchPadDialog.aspx in Ivanti Endpoint Manager 2019.1 and 2020.1 allows an authenticated attacker to gain r…EPSS 5.0%9.8CVE-2024-50330Ivanti endpoint manager sql injection vulnerabilitySQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated at…EPSS 40%9.8CVE-2024-29847Ivanti EPM agent portal deserialization allows unauthenticated RCEThe agent portal in Ivanti Endpoint Manager (EPM) deserializes untrusted data, allowing a remote unauthenticated attacker to execute code. The flaw a…EPSS 53%analysed

Source: NIST National Vulnerability Database (record CVE-2024-29823), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.