PT-2024-38452 · Ivanti · Ivanti Epm

Published

2024-10-08

·

Updated

2024-12-18

·

CVE-2024-7612

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ivanti EPMM versions prior to 12.1.0.4
Description Insecure permissions in Ivanti EPMM allow a local authenticated attacker to modify sensitive application components or access and modify sensitive configuration files without proper authorization.
Recommendations For versions prior to 12.1.0.4, update to version 12.1.0.4 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive application components and configuration files to minimize the risk of exploitation.

Fix

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2024-7612

Affected Products

Ivanti Epm