An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute arbitrary commands on the underlying operating system of the appliance.
Metrics
Affected Vendors & Products
References
History
Thu, 24 Oct 2024 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-285 |
Mon, 12 Aug 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-287 | |
Metrics |
cvssV3_1
|
Thu, 08 Aug 2024 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Ivanti
Ivanti endpoint Manager Mobile |
|
Weaknesses | CWE-285 | |
CPEs | cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:* | |
Vendors & Products |
Ivanti
Ivanti endpoint Manager Mobile |
|
Metrics |
ssvc
|
Wed, 07 Aug 2024 04:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute arbitrary commands on the underlying operating system of the appliance. | |
References |
| |
Metrics |
cvssV3_0
|
MITRE
Status: PUBLISHED
Assigner: hackerone
Published: 2024-08-07T03:54:47.818Z
Updated: 2024-10-24T19:55:26.121Z
Reserved: 2024-05-21T01:04:07.207Z
Link: CVE-2024-36130
Vulnrichment
Updated: 2024-08-08T20:29:36.229Z
NVD
Status : Modified
Published: 2024-08-07T04:17:17.967
Modified: 2024-10-24T20:35:06.217
Link: CVE-2024-36130
Redhat
No data.