PT-2024-5161 · Ivanti · Ivanti Endpoint Manager Mobile

Published

2024-07-17

·

Updated

2024-08-12

·

CVE-2024-34788

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Ivanti Endpoint Manager Mobile (EPMM) versions prior to 12.1.0.1
Description: The issue is related to an improper authentication vulnerability in the web component of EPMM. This vulnerability allows a remote malicious user to access potentially sensitive information. The vulnerability is associated with deficiencies in the authentication procedure, which can be exploited by a remote attacker to gain access to confidential data.
Recommendations: For versions prior to 12.1.0.1, update to version 12.1.0.1 or later to resolve the issue.

Fix

Improper Authentication

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2024-05711
CVE-2024-34788

Affected Products

Ivanti Endpoint Manager Mobile