vulnerability
Ivanti EPM: CVE-2024-29847: Deserialization of Untrusted Data
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 10 | (AV:N/AC:L/Au:N/C:C/I:C/A:C) | Sep 10, 2024 | Sep 20, 2024 | Mar 28, 2025 |
Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
Sep 10, 2024
Added
Sep 20, 2024
Modified
Mar 28, 2025
Description
Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.
Solutions
ivanti-epm-cve-2024-29847-epm-2022ivanti-epm-cve-2024-29847-epm-2024
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.