Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity NewswireSecurity Leadership and ManagementCybersecurity NewsGovernment: Federal, State and Local

Security leaders discuss the new vulnerability added to CISA’s catalog

By Jordyn Alger, Managing Editor
Broken glass

Image via Unsplash

October 8, 2024

The Cybersecurity & Infrastructure Security Agency (CISA) has issued a warning regarding a known, exploited vulnerability. This vulnerability is an Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability (CVE-2024-29824) and has been added to CISA’s Known Exploited Vulnerabilities Catalog.

Security leaders weigh in

Eric Schwake, Director of Cybersecurity Strategy at Salt Security:

“The Ivanti EPM vulnerability is currently being actively exploited and poses a significant threat that requires immediate attention. This is because it allows unauthenticated attackers to execute arbitrary code on unpatched systems, potentially giving them extensive control over affected devices and access to sensitive data. Many organizations could be vulnerable due to the widespread use of Ivanti EPM, especially in enterprise environments.

“Exploiting this flaw could have serious consequences, such as data breaches, disruption of business operations, and further compromise of internal systems. Organizations using Ivanti EPM should prioritize patching their systems immediately and conduct thorough security assessments to detect and mitigate potential compromise. This situation emphasizes the critical importance of proactive vulnerability management and timely patching to protect against evolving threats. In an increasingly interconnected world, securing every IT asset, such as endpoints, applications, and APIs, is paramount to maintaining a strong security posture.”

Jason Soroko, Senior Fellow at Sectigo:

“The CVE-2024-29824 vulnerability in Ivanti Endpoint Manager (EPM) allows remote code execution via SQL Injection, posing serious risk in enterprise environments. Attackers on the same network can fully compromise unpatched EPM systems, leading to broader control. Although Ivanti patched this in May, a proof-of-concept exploit is public, and active exploitation is confirmed. Organizations must patch immediately, as failure to do so leaves systems vulnerable to arbitrary command execution and network-wide compromise. The risk is heightened by published attack methods and ongoing exploitation.”

Mr. Mayuresh Dani, Manager, Security Research, at Qualys Threat Research Unit:

“CVE-2024-29824 is an unauthenticated SQL injection vulnerability, which affects vulnerable Ivanti Endpoint Manager (EPM) appliances. Proof-of-concept code that exploits this vulnerability has been available since early June. Given all these facts, this definitely is a dangerous flaw.

“Multiple versions of proof-of-concept code available make use of different variations of the xp_cmdshell feature in SQL Servers. This primarily allows the attacker to execute arbitrary Windows commands. This means the attacker will be able to download and run scripts that can lead to the installation of malware, or even manipulate files on the endpoint. This functionality can also allow the attacker to exfiltrate data or laterally move to other systems in the network — effectively leading to a complete system compromise. This feature should be disabled on production systems that are externally exposed.”

KEYWORDS: CISA security leaders vulnerability vulnerability assessment vulnerability management

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Jordynalger

Jordyn Alger is the managing editor for Security magazine. Alger writes for topics such as physical security and cyber security and publishes online news stories about leaders in the security industry. She is also responsible for multimedia content and social media posts. Alger graduated in 2021 with a BA in English – Specialization in Writing from the University of Michigan. Image courtesy of Alger

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Top Cybersecurity Leaders
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Columns
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

SEC Podcast Header Podcast

Credential Management in High Turnover Environments

Glowing police siren

Security Isn’t a Commodity. Neither Is Off-Duty Law Enforcement

Soccer stadium

How the Current Iran-US Conflict May Impact World Cup Security

Laptop in darkness

Reframing MFA Bypass: Four Identity Gaps Attackers Exploit

Man with covered face

Why Most Workplace Violence Prevention Starts Too Late

SEC 2026 Benchmark Banner

Events

July 8, 2026

The 2026 Security Maturity Benchmark Report: Insights From Senior Security Leaders

LIVE: July 8, 2026 at 2 pm EDT In this webinar, speakers will share key insights from the report, including why today’s threat environment demands greater maturity and how to evaluate your organization’s current security posture.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • Globe showing Europe

    Security Leaders Discuss the New EU Vulnerability Database

    See More
  • Half open laptop in blue

    SolarWinds Help Desk software vulnerability added to CISA catalogue

    See More
  • Open padlock with keyboard keys

    Security leaders discuss the Cisco security incident

    See More

Events

View AllSubmit An Event
  • July 8, 2026

    The 2026 Security Maturity Benchmark Report: Insights From Senior Security Leaders

    LIVE: July 8, 2026 at 2 pm EDT In this webinar, speakers will share key insights from the report, including why today’s threat environment demands greater maturity and how to evaluate your organization’s current security posture.
View AllSubmit An Event
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing