CVE-2024-36131

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
07/08/2024
Last modified:
21/08/2024

Description

An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary commands on the underlying operating system of the appliance.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:* 12.1.0.1 (excluding)