The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Ivanti Endpoint Manager (EPM) vulnerability to its Known Exploited Vulnerabilities catalog.
The vulnerability (CVE-2024-29824) is an authentication bypass issue in Ivanti EPM, which could allow arbitrary code execution.
Ivanti released security patches in May to address the vulnerability, but no reported attacks have taken place.
CISA orders federal agencies to fix the vulnerability by October 23, 2024.