CyberzSOC

Publication detail
← Back to advisories & guidance

2024-094: Critical Vulnerabilities in Ivanti EPM ↗ source

September 11, 2024 CERT-EU Advisory

Summary

The most severe vulnerability, CVE-2024-29847, with a CVSS score of 10, is due to improper input validation which could lead to deserialisation of untrusted data in the agent portal of Ivanti EPM. It could allow a remote unauthenticated attacker to achieve remote code execution. The vulnerabilities CVE-2024-32840, CVE-2024-32842, CVE-2024-32843, CVE-2024-32845, CVE-2024-32846, CVE-2024-32848 and CVE-2024-34779, with a CVSS score of 9.1, are SQL injection flaws in Ivanti EPM. They could allow an authenticated remote attacker with admin privileges to achieve remote code execution on the server. The following product versions are affected [1]: CERT-EU strongly recommends updating affected devices as soon as possible.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-29847 10.0 Critical Ivanti EPM Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated att…
CVE-2024-32840 9.1 Critical Ivanti EPM An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges…
CVE-2024-32842 9.1 Critical Ivanti EPM An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges…
CVE-2024-32843 9.1 Critical Ivanti EPM An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges…
CVE-2024-32845 9.1 Critical Ivanti EPM An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges…
CVE-2024-32846 9.1 Critical Ivanti EPM An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges…
CVE-2024-32848 9.1 Critical Ivanti EPM An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges…
CVE-2024-34779 9.1 Critical Ivanti EPM An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.