CVE-2024-36131: High severity ivanti endpoint manager mobile (epmm) vulnerability
Published Aug 7, 2024
·Updated
An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary commands on the underlying operating system of the appliance.
Affected Software
1 affected component
Ivanti Endpoint Manager Mobile<12.1.0.1
Event History
Aug 7, 2024
CVE Published
via MITRE·03:54 AM
Data Sourced
via MITRE·03:54 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-36131?
CVE-2024-36131 is considered a critical vulnerability due to its potential for remote command execution.
2
How do I fix CVE-2024-36131?
To fix CVE-2024-36131, ensure you upgrade to Ivanti Endpoint Manager Mobile version 12.1.0.1 or later.
3
Who is affected by CVE-2024-36131?
CVE-2024-36131 affects authenticated users of Ivanti Endpoint Manager Mobile versions prior to 12.1.0.1.
4
What kind of attacks can exploit CVE-2024-36131?
CVE-2024-36131 can be exploited by authenticated remote attackers to execute arbitrary commands on the underlying operating system.
5
What is the nature of CVE-2024-36131?
CVE-2024-36131 is an insecure deserialization vulnerability found in the web component of EPMM.