CVE-2024-29847: Critical severity Ivanti Endpoint Manager vulnerability
Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ivanti EPM agent portalto a version that resolves this vulnerability.Fixed in 2022 SU6Patch 2024 September update
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29847?
CVE-2024-29847 is considered a maximum severity vulnerability that allows remote unauthenticated attackers to execute code remotely.
How do I fix CVE-2024-29847?
To fix CVE-2024-29847, update Ivanti Endpoint Manager to version 2022 SU6 or the September 2024 update.
What types of attacks can CVE-2024-29847 facilitate?
CVE-2024-29847 can facilitate remote code execution attacks due to deserialization of untrusted data.
Which versions of Ivanti Endpoint Manager are affected by CVE-2024-29847?
CVE-2024-29847 affects Ivanti Endpoint Manager versions prior to 2022 SU6 and the 2024 September update.
Is CVE-2024-29847 exploitable without authentication?
Yes, CVE-2024-29847 can be exploited by remote unauthenticated attackers.