Ivanti MobileIron Core clish Restricted Shell Escape via OS Command Injection
CVE-2021-3198
6.5MEDIUM
What is CVE-2021-3198?
By abusing the 'install rpm url' command, an attacker can escape the restricted clish shell on affected versions of Ivanti MobileIron Core. This issue was fixed in version 11.1.0.0.
Affected Version(s)
MobileIron Core 10.7.0.1-9
MobileIron Core 11.0.0.1-3