CVE-2024-36130: Critical severity ivanti endpoint manager mobile (epmm) vulnerability
An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute arbitrary commands on the underlying operating system of the appliance.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36130?
CVE-2024-36130 is categorized as a critical severity vulnerability due to its potential to allow unauthorized remote command execution.
How do I fix CVE-2024-36130?
To mitigate CVE-2024-36130, upgrade Ivanti Endpoint Manager Mobile to version 12.1.0.1 or later.
Who is affected by CVE-2024-36130?
CVE-2024-36130 affects users of Ivanti Endpoint Manager Mobile versions prior to 12.1.0.1.
What type of vulnerability is CVE-2024-36130?
CVE-2024-36130 is an insufficient authorization vulnerability that enables command execution on the underlying operating system.
Can CVE-2024-36130 be exploited remotely?
Yes, CVE-2024-36130 can be exploited by an unauthorized attacker within the network.