CVE-2024-29847

CRITICAL

Ivanti EPM <2022 SU6-2024 September - Code Injection

Title source: llm
STIX 2.1

Description

Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.

Exploits (2)

nomisec WRITEUP 18 stars
by sinsinology · poc
https://github.com/sinsinology/CVE-2024-29847
inthewild WORKING POC
poc
https://github.com/horizon3ai/cve-2024-29847

Scores

CVSS v3 9.8
EPSS 0.6283
EPSS Percentile 98.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-502
Status published
Products (3)
ivanti/endpoint_manager 2022 (6 CPE variants)
ivanti/endpoint_manager 2024
ivanti/endpoint_manager < 2022
Published Sep 12, 2024
Tracked Since Feb 18, 2026