References https://github.com/adysec/POC/blob/main/wpoc/Ivanti/Ivanti-EPM%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(CVE-2024-29824).md https://rivers.chaitin.cn/blog/cqk85a10lnec5jjug450 https://www.tenablecloud.cn/plugins/nessus/197921 https://thehackernews.com/2024/10/ivanti-endpoint-manager-flaw-actively.html https://avd.aliyun.com/detail?id=AVD-2024-29824 https://wh0am1i.com/2024/06/14/CVE-2024-29824-Ivanti-EPM-SQL-Injection-To-RCE/index.html https://cloud.tencent.com/developer/article/2430318 https://www.cnvd.org.cn/flaw/show/CNVD-2024-26099 https://vulners.com/cve/CVE-2024-29824 https://cve.circl.lu/vuln/CVE-2024-29824 https://www.tenablecloud.cn/plugins/was/114433 https://cve.imfht.com/poc_detail/7ccf2c254b4ec19716d74b86d7f7023adb889ce4 https://www.ithome.com.tw/news/163077 https://cve.imfht.com/poc_detail/4e2d66be0fc9af09f82dffe103b6f24faf4b2352?lang=en https://cn-sec.com/archives/tag/cve-2024-29824 https://www.zhousa.com/archives/61443.html
Related VulnerabilitiesPoCCVE-2026-1281: Ivanti EPMM <=12.7.0.0 - Unauthenticated Code InjectionPoCCVE-2026-10520: Ivanti Sentry - OS Command InjectionIvanti Sentry存在操作系统命令注入漏洞(CVE-2026-10520)Ivanti Sentry /mics/api/v2/sentry/mics-config/handleMessage 命令执行漏洞(CVE-2026-10520)Ivanti EPMM /mifs/rs/api/v2/featureusage 命令执行漏洞(CVE-2025-4427)PoCIvanti Endpoint Manager /RemoteControlAuth/api/Auth 权限绕过漏洞(CVE-2026-1603)Ivanti Endpoint Manager 权限管理不当漏洞PoCCVE-2026-1603: Ivanti Endpoint Manager - Authentication BypassIvanti Endpoint Manager Mobile /mifs/c/appstore/fob/3/5/sha256 命令执行漏洞(CVE-2026-1281/CVE-2026-1340)Ivanti Endpoint Manager Mobile 未授权 代码注入漏洞Ivanti多个产品跨站请求伪造漏洞(CVE-2025-8711)(CVE-2025-8712)Ivanti产品权限验证不足漏洞