CVE-2024-22026: Medium severity ivanti endpoint manager mobile (epmm) vulnerability
Published May 22, 2024
·Updated
A local privilege escalation vulnerability in EPMM before 12.1.0.0 allows an authenticated local user to bypass shell restriction and execute arbitrary commands on the appliance.
Affected Software
1 affected component
Ivanti Endpoint Manager Mobile<12.1.0.0
Event History
May 22, 2024
CVE Published
via MITRE·10:55 PM
Data Sourced
via MITRE·10:55 PM
DescriptionSeverity
Data Sourced
via NVD·11:15 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-22026?
CVE-2024-22026 is classified as a local privilege escalation vulnerability.
2
How do I fix CVE-2024-22026?
To fix CVE-2024-22026, upgrade Ivanti Endpoint Manager Mobile to version 12.1.0.0 or later.
3
Who is affected by CVE-2024-22026?
CVE-2024-22026 affects authenticated local users of Ivanti Endpoint Manager Mobile versions prior to 12.1.0.0.
4
What kind of attacks can be executed using CVE-2024-22026?
Exploitation of CVE-2024-22026 allows an authenticated local user to bypass shell restrictions and execute arbitrary commands.
5
What versions of Ivanti Endpoint Manager Mobile are vulnerable to CVE-2024-22026?
Ivanti Endpoint Manager Mobile versions before 12.1.0.0 are vulnerable to CVE-2024-22026.