VulnerabilityModified
CVE-2024-29823
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
HIGH 8.8EPSS 99.9%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 99.9%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 99.86% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- ivanti/endpoint manager
- Source
- support@hackerone.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.