CVE-2022-30121: Medium severity ivanti endpoint manager (epm) vulnerability
The “LANDesk(R) Management Agent” service exposes a socket and once connected, it is possible to launch commands only for signed executables. This is a security bug that allows a limited user to get escalated admin privileges on their system.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this security bug?
The vulnerability ID for this security bug is CVE-2022-30121.
What is the affected software?
The affected software is Ivanti Endpoint Manager.
What versions of Ivanti Endpoint Manager are affected?
Versions 2021.1.1, 2021.1.1-su1, and 2021.1.1-su2 of Ivanti Endpoint Manager are affected.
What privileges can a limited user gain with this vulnerability?
A limited user can gain escalated admin privileges on their system with this vulnerability.
What is the severity of CVE-2022-30121?
The severity of CVE-2022-30121 is medium (6.7).
Is there a security advisory available for this vulnerability?
Yes, there is a security advisory available for this vulnerability. You can find it at: https://forums.ivanti.com/s/article/Security-Advisory-for-Ivanti-Endpoint-Manager-Client-CVE-2022-30121?language=en_US