CVE-2021-3198: Ivanti MobileIron Core clish Restricted Shell Escape via OS Command Injection
By abusing the 'install rpm url' command, an attacker can escape the restricted clish shell on affected versions of Ivanti MobileIron Core. This issue was fixed in version 11.1.0.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ivanti MobileIron Coreto a version that resolves this vulnerability.Fixed in 11.1.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2021-3198?
CVE-2021-3198 has a high severity rating due to its potential for privilege escalation.
How do I fix CVE-2021-3198?
To fix CVE-2021-3198, upgrade to Ivanti MobileIron Core version 11.1.0.0 or later.
What versions of Ivanti MobileIron are affected by CVE-2021-3198?
CVE-2021-3198 affects Ivanti MobileIron versions up to 10.7.0.1-9 and from 11.0.0.0 up to 11.1.0.0.
Can CVE-2021-3198 be exploited remotely?
Yes, CVE-2021-3198 can be exploited remotely by attackers through the restricted clish shell.
What are the potential impacts of CVE-2021-3198?
Exploitation of CVE-2021-3198 may allow an attacker to gain unauthorized access and perform actions with elevated privileges.