Skip to main content

Vulnerabilities could allow an attacker to execute arbitrary commands, bypass authentication, and access sensitive resources

Summary

Vulnerabilities could allow an attacker to execute arbitrary commands, bypass authentication, and access sensitive resources

Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

Ivanti has disclosed four vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM), formerly known as MobileIron Core. The advisory addresses three high severity vulnerabilities and one medium severity. Ivanti EPMM is a mobile management software engine that enables IT to set policies for mobile devices, applications, and content. 

Additionally, CVE-2024-34788 has a CVSSv3 score of 5.5 and could allow remote attacker to access potentially sensitive information.

Remediation advice

Affected organisations are encouraged to review the following Security Advisory Ivanti Endpoint Manager for Mobile (EPMM) July 2024 and apply the relevant updates.

Definitive source of threat updates

CVE Vulnerabilities

Last edited: 19 July 2024 1:44 pm