PT-2024-5044 · Ivanti · Ivanti Epm
Published
2024-05-15
·
Updated
2024-06-17
·
CVE-2024-22026
CVSS v2.0
6.8
Medium
| Vector | AV:L/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Ivanti EPMM versions prior to 12.1.0.0
Description:
A local privilege escalation issue in Ivanti EPMM allows an authenticated local user to bypass shell restriction and execute arbitrary commands on the appliance. This is related to insufficient access control in the application. The exploitation of this issue may allow an attacker to bypass existing security restrictions and execute arbitrary commands using specially crafted RPM packages.
Recommendations:
For versions prior to 12.1.0.0, update to version 12.1.0.0 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the appliance to minimize the risk of exploitation.
Exploit
Fix
Improper Access Control
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ivanti Epm