First published: Wed Jun 02 2021(Updated: )
By abusing the 'install rpm url' command, an attacker can escape the restricted clish shell on affected versions of Ivanti MobileIron Core. This issue was fixed in version 11.1.0.0.
Credit: cve@rapid7.con
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti MobileIron | <=10.7.0.1-9 | |
Ivanti MobileIron | >=11.0.0.0<11.1.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3198 has a high severity rating due to its potential for privilege escalation.
To fix CVE-2021-3198, upgrade to Ivanti MobileIron Core version 11.1.0.0 or later.
CVE-2021-3198 affects Ivanti MobileIron versions up to 10.7.0.1-9 and from 11.0.0.0 up to 11.1.0.0.
Yes, CVE-2021-3198 can be exploited remotely by attackers through the restricted clish shell.
Exploitation of CVE-2021-3198 may allow an attacker to gain unauthorized access and perform actions with elevated privileges.