First published: Wed Dec 08 2021(Updated: )
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
Credit: support@hackerone.com support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti Endpoint Manager Cloud Services Appliance | <=4.5 | |
Ivanti Endpoint Manager Cloud Services Appliance | =4.6 | |
Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) | ||
<=4.5 | ||
=4.6 |
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.