First published: Mon Jun 03 2019(Updated: )
Use of a hard-coded encryption key in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to full managed endpoint compromise by an authenticated user with read privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti LANDESK Management Suite | =10.0.1.168-service_update_5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-12376 has been classified as a critical vulnerability due to the potential for full managed endpoint compromise.
To mitigate CVE-2019-12376, upgrade Ivanti LANDESK Management Suite to a version that does not use a hard-coded encryption key.
CVE-2019-12376 affects users of Ivanti LANDESK Management Suite version 10.0.1.168 Service Update 5.
Yes, an authenticated user with read privileges can exploit CVE-2019-12376 to compromise the managed endpoints.
The implications of CVE-2019-12376 include potential full control over managed endpoints, leading to data breach or unauthorized access.