Home

Description

Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.

PUBLISHED Reserved 2024-03-21 | Published 2024-09-12 | Updated 2024-09-17 | Assigner hackerone




CRITICAL: 10.0CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Product status

Default status
unaffected

2024 September Security Update (custom) before 2024 September Security Update
affected

2022 SU6 (custom) before 2022 SU6
affected

References

forums.ivanti.com/...eptember-2024-for-EPM-2024-and-EPM-2022

cve.org (CVE-2024-29847)

nvd.nist.gov (CVE-2024-29847)

Download JSON