Vulnerabilities could allow an attacker to execute arbitrary commands, bypass authentication, and access sensitive resources
Summary
Vulnerabilities could allow an attacker to execute arbitrary commands, bypass authentication, and access sensitive resources
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Ivanti has disclosed four vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM), formerly known as MobileIron Core. The advisory addresses three high severity vulnerabilities and one medium severity. Ivanti EPMM is a mobile management software engine that enables IT to set policies for mobile devices, applications, and content.
Additionally, CVE-2024-34788 has a CVSSv3 score of 5.5 and could allow remote attacker to access potentially sensitive information.
Remediation advice
Affected organisations are encouraged to review the following Security Advisory Ivanti Endpoint Manager for Mobile (EPMM) July 2024 and apply the relevant updates.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 19 July 2024 1:44 pm