PT-2024-38452 · Ivanti · Ivanti Epm
Published
2024-10-08
·
Updated
2024-12-18
·
CVE-2024-7612
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ivanti EPMM versions prior to 12.1.0.4
Description
Insecure permissions in Ivanti EPMM allow a local authenticated attacker to modify sensitive application components or access and modify sensitive configuration files without proper authorization.
Recommendations
For versions prior to 12.1.0.4, update to version 12.1.0.4 or later to resolve the issue.
As a temporary workaround, consider restricting access to sensitive application components and configuration files to minimize the risk of exploitation.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ivanti Epm