CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-29827

Medium Severity
Ivanti
SVRS
30/100

CVSSv3
8.8/10

EPSS
0.00553/1

CVE-2024-29827: SQL Injection in Ivanti EPM allows unauthenticated remote code execution. This SQL Injection vulnerability impacts Ivanti EPM 2022 SU5 and earlier, posing a critical risk. An attacker on the same network can exploit this unauthenticated flaw to execute arbitrary code on the Core server. Despite a relatively low SOCRadar Vulnerability Risk Score (SVRS) of 30, indicating less real-world exploit activity currently, the high CVSS score of 8.8 signals significant technical severity. Immediate patching is recommended for affected Ivanti EPM versions to mitigate potential remote code execution attacks. This flaw is dangerous because it lets attackers compromise systems without needing login credentials if they are on the same network.

In The Wild
CVSS:3.1
AV:A
AC:L
PR:N
UI:N
S:U
C:H
I:H
A:H
2024-05-31

2024-10-03
Eye Icon
SOCRadar
AI Insight

Description

CVE-2024-29827 is a vulnerability with a CVSS score of 0, indicating a low severity. However, SOCRadar's SVRS assigns it a score of 44, highlighting the potential for exploitation. This discrepancy stems from SOCRadar's integration of additional intelligence sources, including social media, news, and dark web data.

Key Insights

  • Active Exploitation: The vulnerability is actively exploited in the wild, posing an immediate threat to organizations.
  • Low CVSS Score: The CVSS score of 0 may underestimate the severity of the vulnerability, as it does not consider the broader context and intelligence gathered by SOCRadar.
  • SVRS Score: The SVRS score of 44 indicates a moderate level of risk, warranting attention and prompt mitigation.
  • Threat Actors: Specific threat actors or APT groups exploiting this vulnerability have not been identified at this time.

Mitigation Strategies

  • Apply Software Updates: Install the latest software updates from the vendor to patch the vulnerability.
  • Enable Intrusion Detection Systems (IDS): Configure IDS to detect and block malicious activity targeting the vulnerable software.
  • Restrict Network Access: Limit network access to critical systems and services to reduce the attack surface.
  • Implement Multi-Factor Authentication (MFA): Enforce MFA to prevent unauthorized access to sensitive systems and data.

Additional Information

If users have additional queries regarding this incident, they can use the 'Ask to Analyst' feature, contact SOCRadar directly, or open a support ticket for more information if necessary.

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

Ivanti Patches Critical Flaws in Endpoint Manager, Other Products
ddos2024-05-27
Ivanti Patches Critical Flaws in Endpoint Manager, Other Products | On May 21, Ivanti released updates to address numerous critical vulnerabilities in products such as Endpoint Manager, Avalanche, Neurons for ITSM, Connect Secure, and Secure Access. In total, 16 vulnerabilities were patched, which we... The post Ivanti Patches Critical Flaws in Endpoint Manager, Other Products appeared first on InfoTech & InfoSec News.On May 21
cve-2024-22060
cve-2023-38551
cve-2023-46810
cve-2024-29829
CVE-2024-29827 | Ivanti Endpoint Manager GetDBPatchProducts sql injection
vuldb.com2024-05-25
CVE-2024-29827 | Ivanti Endpoint Manager GetDBPatchProducts sql injection | A vulnerability has been found in Ivanti Endpoint Manager and classified as critical. Affected by this vulnerability is the function GetDBPatchProducts. The manipulation leads to sql injection. This vulnerability is known as CVE-2024-29827. The attack can be launched remotely. There is no exploit available. It is recommended to upgrade the affected component.
cve-2024-29827
domains
urls
cves
ZDI-24-510: Ivanti Endpoint Manager GetDBPatchProducts SQL Injection Remote Code Execution Vulnerability
2024-05-24
ZDI-24-510: Ivanti Endpoint Manager GetDBPatchProducts SQL Injection Remote Code Execution Vulnerability | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Endpoint Manager. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2024-29827.
zerodayinitiative.com
rss
forum
news
Privacy nightmare or useful tool? - The CyberWire
2024-05-22
Privacy nightmare or useful tool? - The CyberWire | Description: Some say Microsoft’s Recall should be. A breach of a Texas healthcare provided affects over four hundred thousand. Police in the Philippines shut down services following a breach. Ivanti patches multiple products. GitHub fixes a critical authentication bypass vulnerability. Researchers discover critical vulnerabilities in Honeywell’s ControlEdge Unit Operations Controller. The DoD releases their Cybersecurity Reciprocity Playbook. Hackers leak a database with millions of Americans’ criminal records. Mastercard speeds fraud detection with AI. On our Learning Layer segment, host Sam Meisenberg and Joe Carrigan continue their discussion of Joe's ISC2
google.com
rss
forum
news
Critical SQL Injection flaws impact Ivanti Endpoint Manager (EPM)
Pierluigi Paganini2024-05-23
Critical SQL Injection flaws impact Ivanti Endpoint Manager (EPM) | Ivanti addressed multiple flaws in the Endpoint Manager (EPM), including remote code execution vulnerabilities. Ivanti this week rolled out security patches to address multiple critical vulnerabilities in the Endpoint Manager (EPM). A remote attacker can exploit the flaws to gain code execution under certain conditions. Below is the list of the addressed vulnerabilities: CVE Description […] Ivanti addressed multiple flaws in the Endpoint Manager (EPM), including
securityaffairs.co
rss
forum
news
Ivanti Patches Critical Remote Code Execution Flaws in Endpoint Manager
Ajit Jasrotia2024-05-23
Ivanti Patches Critical Remote Code Execution Flaws in Endpoint Manager | Ivanti on Tuesday rolled out fixes to address multiple critical security flaws in Endpoint Manager (EPM) that could be exploited to achieve remote code execution under certain circumstances. Six of the 10 vulnerabilities – from CVE-2024-29822 through CVE-2024-29827 (CVSS scores: 9.6) – relate to SQL injection flaws that allow an unauthenticated attacker within the same […] The post Ivanti Patches Critical Remote Code Execution Flaws in Endpoint Manager appeared
cve-2024-29828
cve-2024-29848
cve-2024-29822
cve-2023-46810
Ivanti Endpoint Manager SQL Injection Flaw Let Attackers Execute Arbitrary Code
Eswar2024-05-22
Ivanti Endpoint Manager SQL Injection Flaw Let Attackers Execute Arbitrary Code | Multiple vulnerabilities involving SQL injection have been identified in Ivanti Endpoint Manager. These vulnerabilities could potentially enable malicious actors to carry out various unauthorized actions, including initiating Denial of Service attacks and executing arbitrary code on affected systems. One of the vulnerabilities found was a SQL injection vulnerability in Ivanti Neurons for ITSM, while the [&#8230;] The post Ivanti Endpoint Manager SQL Injection Flaw Let Attackers Execute Arbitrary Code</a
cybersecuritynews.com
rss
forum
news

Social Media

On May 21, Ivanti disclosed six critical-severity SQL injection vulnerabilities affecting Ivanti Endpoint Manager, specifically versions 2022 SU5 and earlier. These vulnerabilities, CVE-2024-29822 through CVE-2024-29827, have a CVSS score of 9.6. https://t.co/yZ3o83hTlY
0
0
0
[ZDI-24-510|CVE-2024-29827] Ivanti Endpoint Manager GetDBPatchProducts SQL Injection Remote Code Execution Vulnerability (CVSS 9.8; Credit: 06fe5fd2bc53027c4a3b7e395af0b850e7b8a044) https://t.co/yvuGLV6AWG
0
0
1
CVE-2024-29827 An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code. https://t.co/xAOMEP3bny
0
0
0
🔥 #Ivanti released patches for multiple critical security flaws (CVE-2024-29822 through CVE-2024-29827) in Endpoint Manager (EPM) — 6 of these are #SQLinjection vulnerabilities that allow RCE without authentication. https://t.co/g7V9Ygmspl #hacking #cybersecurity
0
0
0
Six of the 10 vulnerabilities – from CVE-2024-29822 through CVE-2024-29827 (CVSS scores: 9.6) – relate to SQL injection flaws that allow an unauthenticated attacker within the same network to execute arbitrary code. https://t.co/kJBB7JDagI
0
0
0
Tracked as CVE-2024-29822 through CVE-2024-29827, the bugs impact the Core server of Ivanti EPM 2022 SU5 and previous releases, and have a CVSS score of 9.6. https://t.co/fDttErZcW9
0
0
0

Affected Software

Configuration 1
TypeVendorProduct
AppIvantiendpoint_manager

References

ReferenceLink
[email protected]https://forums.ivanti.com/s/article/Security-Advisory-May-2024

CWE Details

CWE IDCWE NameDescription
CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')The software constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence