Unauth Exec via EPMM Web Component <12.1.0.1
CVE-2024-36130 Published on August 7, 2024

An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute arbitrary commands on the underlying operating system of the appliance.

NVD

Weakness Type

What is an AuthZ Vulnerability?

The software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

CVE-2024-36130 has been classified to as an AuthZ vulnerability or weakness.


Products Associated with CVE-2024-36130

Want to know whenever a new CVE is published for Ivanti Endpoint Manager Mobile? stack.watch will email you.

 

Affected Versions

Ivanti EPMM: ivanti endpoint_manager_mobile:

Exploit Probability

EPSS
2.23%
Percentile
84.26%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.