← Vulnerability feed

Vulnerability record · CVE-2024-29847 · published 12 September 2024

CVE-2024-29847: Ivanti EPM agent portal deserialization allows unauthenticated RCE

Ivanti · Endpoint Manager

The agent portal in Ivanti Endpoint Manager (EPM) deserializes untrusted data, allowing a remote unauthenticated attacker to execute code. The flaw affects versions before 2022 SU6 and the 2024 September update, and carries a critical CVSS score of 9.8.

9.8 CVSS 3.1 Critical EPSS 53% · top 1.1% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score
53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityCVSS 9.8 with unauthenticated network RCE and high EPSS probability make this a top remediation priority despite no KEV listing.

What it is

The agent portal in Ivanti Endpoint Manager (EPM) deserializes untrusted data, allowing a remote unauthenticated attacker to execute code. The flaw affects versions before 2022 SU6 and the 2024 September update, and carries a critical CVSS score of 9.8.

Impact

An attacker gains remote code execution on the EPM server, which can lead to full compromise of the endpoint management infrastructure and any managed endpoints.

Attack surface

Reachable over the network through the agent portal with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N.

Exploitation

Not listed in CISA KEV and no public exploit references are provided, but EPSS is 0.529 (98.9th percentile), indicating elevated likelihood of exploitation activity.

What to do

  • Apply the Ivanti EPM 2022 SU6 or 2024 September update per the vendor advisory.
  • Restrict network access to the EPM agent portal to trusted management networks only.
  • Monitor EPM server logs for anomalous deserialization or process execution activity.
  • Isolate or segment EPM servers from general user networks to limit lateral movement.

Detection

  • Hunt for unexpected child processes spawned by the EPM agent portal service (e.g., cmd.exe, powershell.exe).
  • Monitor for inbound connections to the EPM agent portal from untrusted or external IP addresses.
  • Review EPM server logs for deserialization errors or unusual agent portal requests.
  • Alert on new or modified files in EPM web directories or temporary folders.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-29847 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2024-29824Ivanti Endpoint Manager Core Server SQL Injection Enables RCEIvanti Endpoint Manager 2022 SU5 and earlier contains an unspecified SQL injection in the Core server. An unauthenticated attacker on the same networ…KEVEPSS 100%analysed7.5CVE-2026-1603Ivanti Endpoint Manager authentication bypass leaks stored credentialsIvanti Endpoint Manager before 2024 SU5 contains an authentication bypass (CWE-288/CWE-306) that lets a remote, unauthenticated attacker reach a func…KEVEPSS 88%analysed7.5CVE-2024-13159Ivanti EPM absolute path traversal leaks sensitive filesIvanti Endpoint Manager (EPM) contains an absolute path traversal flaw (CWE-36) that lets a remote attacker read files outside the intended directory…KEVEPSS 100%analysed7.5CVE-2024-13160Ivanti Endpoint Manager absolute path traversal information leakIvanti Endpoint Manager (EPM) contains an absolute path traversal flaw (CWE-36) that allows a remote, unauthenticated attacker to read files outside …KEVEPSS 91%analysed7.5CVE-2024-13161Ivanti Endpoint Manager absolute path traversal leaks sensitive filesIvanti Endpoint Manager (EPM) contains an absolute path traversal flaw (CWE-36) that lets a remote attacker read files outside the intended directory…KEVEPSS 90%analysed9.9CVE-2020-13774Ivanti endpoint manager unrestricted file upload vulnerabilityAn unrestricted file-upload issue in EditLaunchPadDialog.aspx in Ivanti Endpoint Manager 2019.1 and 2020.1 allows an authenticated attacker to gain r…EPSS 5.0%9.8CVE-2024-50330Ivanti endpoint manager sql injection vulnerabilitySQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated at…EPSS 40%9.8CVE-2024-8191Ivanti endpoint manager sql injection vulnerabilitySQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achie…EPSS 20%

Source: NIST National Vulnerability Database (record CVE-2024-29847), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.