Ivanti MobileIron Core clish Restricted Shell Escape via OS Command Injection
CVE-2021-3198

6.5MEDIUM

Key Information:

Vendor
Ivanti
Vendor
CVE Published:
2 June 2021

Summary

By abusing the 'install rpm url' command, an attacker can escape the restricted clish shell on affected versions of Ivanti MobileIron Core. This issue was fixed in version 11.1.0.0.

Affected Version(s)

MobileIron Core 10.7.0.1-9

MobileIron Core 11.0.0.1-3

References

EPSS Score

1% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database

Credit

William Vu of Rapid7
.