CVE-2021-3540: Ivanti MobileIron Core clish Restricted Shell Escape via Argument Injection
By abusing the 'install rpm info detail' command, an attacker can escape the restricted clish shell on affected versions of Ivanti MobileIron Core. This issue was fixed in version 11.1.0.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ivanti MobileIron Coreto a version that resolves this vulnerability.Fixed in 11.1.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2021-3540?
CVE-2021-3540 is a high severity vulnerability due to the potential for privilege escalation.
How do I fix CVE-2021-3540?
To fix CVE-2021-3540, upgrade Ivanti MobileIron to version 11.1.0.0 or later.
Which versions of Ivanti MobileIron are affected by CVE-2021-3540?
Versions up to 10.7.0.1-9 and versions from 11.0.0.0 to below 11.1.0.0 are affected by CVE-2021-3540.
What type of vulnerability is CVE-2021-3540?
CVE-2021-3540 is classified as a privilege escalation vulnerability.
What can an attacker achieve by exploiting CVE-2021-3540?
An attacker exploiting CVE-2021-3540 can escape the restricted clish shell, potentially gaining unauthorized access.