CVE-2024-29825
50Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.6epss 100%
exploitation probability
100%top 1% of all CVEs
observed exploitation
nono source reports it
In short
A security flaw in Ivanti EPM 2022 SU5 and earlier versions allows someone on the same network to inject malicious SQL commands without logging in, potentially taking complete control of the system.
Technical detail
An unauthenticated SQL injection vulnerability in the Core server component permits an attacker within the network perimeter to execute arbitrary SQL queries, escalating to remote code execution. The vulnerability affects Ivanti EPM 2022 SU5 and prior versions without authentication requirements.
Summary generated and translated by AI from the official description.
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
Ivanti · EPM