← back
CVE-2024-29826criticalCWE-89

CVE-2024-29826

50Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.6epss 100%
exploitation probability
100%top 1% of all CVEs
observed exploitation
nono source reports it
In short

A SQL Injection flaw in Ivanti EPM 2022 SU5 lets someone on the same network inject malicious commands into the database without logging in, potentially taking complete control of the system.

Technical detail

An unauthenticated SQL Injection vulnerability in the Core server component allows a network-adjacent attacker to manipulate SQL queries and execute arbitrary code through the database layer, achieving system compromise without authentication credentials.

Summary generated and translated by AI from the official description.
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
Ivanti · EPM