← Zuruck zu CVEs
CVE-2024-36130
CRITICAL9.8
Beschreibung
An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute arbitrary commands on the underlying operating system of the appliance.
CVE Details
CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht8/7/2024
Zuletzt geandert3/13/2025
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
ivanti:endpoint_manager_mobile
Schwachen (CWE)
CWE-287CWE-285
Referenzen
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.