CVE-2024-36130

An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute arbitrary commands on the underlying operating system of the appliance.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:*

History

12 Aug 2024, 18:52

Type Values Removed Values Added
First Time Ivanti
Ivanti endpoint Manager Mobile
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:*
References () https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-for-Mobile-EPMM-July-2024 - () https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-for-Mobile-EPMM-July-2024 - Vendor Advisory
CWE CWE-287

07 Aug 2024, 04:17

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-07 04:17

Updated : 2025-03-13 21:15


NVD link : CVE-2024-36130

Mitre link : CVE-2024-36130


JSON object : View

Products Affected

ivanti

  • endpoint_manager_mobile
CWE
CWE-287

Improper Authentication