Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity NewswireSecurity Leadership and ManagementCybersecurity NewsGovernment: Federal, State and Local

Security leaders discuss the new vulnerability added to CISA’s catalog

By Jordyn Alger, Managing Editor
Broken glass

Image via Unsplash

October 8, 2024

The Cybersecurity & Infrastructure Security Agency (CISA) has issued a warning regarding a known, exploited vulnerability. This vulnerability is an Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability (CVE-2024-29824) and has been added to CISA’s Known Exploited Vulnerabilities Catalog.

Security leaders weigh in

Eric Schwake, Director of Cybersecurity Strategy at Salt Security:

“The Ivanti EPM vulnerability is currently being actively exploited and poses a significant threat that requires immediate attention. This is because it allows unauthenticated attackers to execute arbitrary code on unpatched systems, potentially giving them extensive control over affected devices and access to sensitive data. Many organizations could be vulnerable due to the widespread use of Ivanti EPM, especially in enterprise environments.

“Exploiting this flaw could have serious consequences, such as data breaches, disruption of business operations, and further compromise of internal systems. Organizations using Ivanti EPM should prioritize patching their systems immediately and conduct thorough security assessments to detect and mitigate potential compromise. This situation emphasizes the critical importance of proactive vulnerability management and timely patching to protect against evolving threats. In an increasingly interconnected world, securing every IT asset, such as endpoints, applications, and APIs, is paramount to maintaining a strong security posture.”

Jason Soroko, Senior Fellow at Sectigo:

“The CVE-2024-29824 vulnerability in Ivanti Endpoint Manager (EPM) allows remote code execution via SQL Injection, posing serious risk in enterprise environments. Attackers on the same network can fully compromise unpatched EPM systems, leading to broader control. Although Ivanti patched this in May, a proof-of-concept exploit is public, and active exploitation is confirmed. Organizations must patch immediately, as failure to do so leaves systems vulnerable to arbitrary command execution and network-wide compromise. The risk is heightened by published attack methods and ongoing exploitation.”

Mr. Mayuresh Dani, Manager, Security Research, at Qualys Threat Research Unit:

“CVE-2024-29824 is an unauthenticated SQL injection vulnerability, which affects vulnerable Ivanti Endpoint Manager (EPM) appliances. Proof-of-concept code that exploits this vulnerability has been available since early June. Given all these facts, this definitely is a dangerous flaw.

“Multiple versions of proof-of-concept code available make use of different variations of the xp_cmdshell feature in SQL Servers. This primarily allows the attacker to execute arbitrary Windows commands. This means the attacker will be able to download and run scripts that can lead to the installation of malware, or even manipulate files on the endpoint. This functionality can also allow the attacker to exfiltrate data or laterally move to other systems in the network — effectively leading to a complete system compromise. This feature should be disabled on production systems that are externally exposed.”

KEYWORDS: CISA security leaders vulnerability vulnerability assessment vulnerability management

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Jordynalger

Jordyn Alger is the managing editor for Security magazine. Alger writes for topics such as physical security and cyber security and publishes online news stories about leaders in the security industry. She is also responsible for multimedia content and social media posts. Alger graduated in 2021 with a BA in English – Specialization in Writing from the University of Michigan. Image courtesy of Alger

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Columns
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Executive Protection

Beyond the Bodyguard: Why Executive Protection Requires a New Playbook

Person in red hoodie

When Metal Theft Becomes a Life Safety Crisis

Stacked books

Safe Learning 101 Program Supports Schools in Strengthening Campus Security

American flag

ICE Acting Director Todd Lyons to Resign

Man silhouette

Former UK Ambassador, Linked to Epstein, Failed Security Vetting Yet Received Clearance

SEC 2026 Benchmark Banner
SEC 2026 Benchmark Banner

Events

May 12, 2026

Managing Large Scale Events in 2026: Security, Travel and Threat Intelligence

As the Americas prepare to host the world’s biggest football tournament in 2026, security, resilience, and travel risk leaders face a fast-moving threat environment that extends well beyond the stadiums. Learn the risks and readiness considerations that matter most.

May 21, 2026

From Referral to Response: Managing Domestic Violence Threats in the Workplace

Domestic violence remains a complex driver of workplace violence, creating high-risk scenarios that require coordination across departments without clear ownership. Learn how threat management teams can manage domestic violence referrals from the start.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products
Solutions by Sector webinar promo


The Role of AI and Video - Free Webinar - June 3, 2026

Related Articles

  • Coding

    WhatsApp Flaw Added to CISA’s Known Exploited Vulnerabilities Catalog

    See More
  • Globe showing Europe

    Security Leaders Discuss the New EU Vulnerability Database

    See More
  • Half open laptop in blue

    SolarWinds Help Desk software vulnerability added to CISA catalogue

    See More

Related Products

See More Products
  • facility manager.jpg

    The Facility Manager's Guide to Safety and Security

  • The Complete Guide to Physical Security

  • into to sec.jpg

    Introduction to Security, 10th Edition

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing