CVE-2024-36130

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
07/08/2024
Last modified:
13/03/2025

Description

An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute arbitrary commands on the underlying operating system of the appliance.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:* 12.1.0.1 (excluding)