CVE-2024-7612: High severity ivanti endpoint manager mobile (epmm) vulnerability
Published Oct 8, 2024
·Updated
Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application components.
Affected Software
2 affected components
Ivanti Endpoint Manager Mobile<12.0.0.5
Ivanti Endpoint Manager Mobile>=12.1.0.0<12.1.0.4
Event History
Oct 8, 2024
CVE Published
via MITRE·04:17 PM
Data Sourced
via MITRE·04:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-7612?
CVE-2024-7612 is considered a medium-severity vulnerability due to its potential impact on sensitive application components.
2
How do I fix CVE-2024-7612?
To fix CVE-2024-7612, upgrade Ivanti Endpoint Manager Mobile to version 12.1.0.4 or later.
3
Who is affected by CVE-2024-7612?
CVE-2024-7612 affects all versions of Ivanti Endpoint Manager Mobile prior to 12.1.0.4 and in versions up to 12.0.0.5.
4
What type of attacks can exploit CVE-2024-7612?
CVE-2024-7612 can be exploited by local authenticated attackers to modify sensitive application components.
5
What mitigation strategies exist for CVE-2024-7612?
Mitigation for CVE-2024-7612 includes applying the latest patches from Ivanti and enforcing strict access controls.