{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aivantiendpoint_manager/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*:*","cpe:2.3:a:ivanti:endpoint_manager:2022:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2024-29826"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["U-Boot"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["DENX"],"content_html":"\u003cp\u003eThe BSI has reported a high-severity vulnerability affecting DENX U-Boot, a widely used open-source bootloader for embedded systems. The flaw, identified as CVE-2024-29826, permits an unauthenticated attacker located on an adjacent network to execute arbitrary code. This vulnerability is particularly critical because it occurs at the bootloader level, granting an attacker full control over the hardware before the operating system initializes. Because U-Boot is pervasive in industrial control systems, networking equipment, and IoT devices, successful exploitation could lead to persistent compromise, unauthorized access to system resources, or complete device bricking. Organizations relying on hardware using U-Boot should evaluate their firmware update cycles and restrict network access to sensitive boot management interfaces.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to gain full control over affected embedded devices, leading to potential data exfiltration, permanent persistent access, or complete service disruption. The risk is elevated for industrial and enterprise infrastructure sectors where U-Boot is standard.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all devices in the infrastructure that utilize DENX U-Boot for firmware and boot management.\u003c/li\u003e\n\u003cli\u003eApply firmware patches provided by the hardware vendor once they address CVE-2024-29826.\u003c/li\u003e\n\u003cli\u003eImplement network segmentation to isolate devices from untrusted or unauthorized adjacent network segments to prevent access by malicious actors.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-29T16:17:52Z","date_published":"2026-09-29T16:17:52Z","id":"https://feed.craftedsignal.io/briefs/2026-09-denx-u-boot-rce/","summary":"A high-severity vulnerability, CVE-2024-29826, in DENX U-Boot allows an attacker on an adjacent network to achieve arbitrary code execution.","title":"Remote Code Execution Vulnerability in DENX U-Boot","url":"https://feed.craftedsignal.io/briefs/2026-09-denx-u-boot-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}