CyberzSOC

Publication detail
← Back to advisories & guidance

2024-072: Vulnerabilities in Ivanti EPMM ↗ source

July 22, 2024 CERT-EU Advisory

Summary

These vulnerabilities could lead to remote code execution, authentication bypass, and sensitive information leakage. The vulnerability CVE-2024-36130, with a CVSS score of 9.8, is a flaw (insufficient authorisation checks) in the web component of EPMM that would allow an unauthorised attacker within the network to execute arbitrary commands on the underlying operating system of the The vulnerability CVE-2024-36131, with a CVSS score of 8.8, is a flaw (insecure deserialisation) in the web component of EPMM that would allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system of the appliance [1]. The vulnerability CVE-2024-36132, with a CVSS score of 8.2, is a flaw (insufficient checks) in the authentication controls of EPMM that would allow a remote attacker to bypass authentication and access sensitive resources [1]. The vulnerability CVE-2024-34788, with a CVSS score of 5.3, is a flaw (improper authentication) in the web component of EPMM that would allow a remote malicious user to access potentially sensitive information [1]. These vulnerabilities affect EPMM versions prior to 12.1.0.1 [1].

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-36130 9.8 Critical Ivanti EPMM An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute …
CVE-2024-36131 8.8 High Ivanti EPMM An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary com…
CVE-2024-36132 8.2 High Ivanti EPMM Insufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authentication and access sensitive…
CVE-2024-34788 5.3 Medium Ivanti EPMM An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to access potentially sensitive in…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.