PT-2024-5160 · Ivanti · Ivanti Endpoint Manager Mobile

Published

2024-07-17

·

Updated

2024-08-12

·

CVE-2024-36132

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:C/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Ivanti Endpoint Manager Mobile (EPMM) versions prior to 12.1.0.1
Description: The issue is related to insufficient verification of authentication controls, which can be exploited by a remote attacker to bypass the authentication process and gain access to sensitive resources.
Recommendations: For versions prior to 12.1.0.1, update to version 12.1.0.1 or later to resolve the issue.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-05710
CVE-2024-36132

Affected Products

Ivanti Endpoint Manager Mobile