PT-2024-5044 · Ivanti · Ivanti Epm

Published

2024-05-15

·

Updated

2024-06-17

·

CVE-2024-22026

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Ivanti EPMM versions prior to 12.1.0.0
Description: A local privilege escalation issue in Ivanti EPMM allows an authenticated local user to bypass shell restriction and execute arbitrary commands on the appliance. This is related to insufficient access control in the application. The exploitation of this issue may allow an attacker to bypass existing security restrictions and execute arbitrary commands using specially crafted RPM packages.
Recommendations: For versions prior to 12.1.0.0, update to version 12.1.0.0 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the appliance to minimize the risk of exploitation.

Exploit

Fix

Improper Access Control

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-05571
CVE-2024-22026

Affected Products

Ivanti Epm