Insecure Permissions in Ivanti EPMM Allow Unauthorized Access to Sensitive Configuration Files
CVE-2024-7612

7.8HIGH

Key Information:

Vendor
Ivanti
Vendor
CVE Published:
8 October 2024

Summary

The vulnerability in Ivanti Endpoint Manager Mobile (EPMM) arises from improperly configured permissions that potentially allow a local authenticated attacker to modify sensitive application components. With this flaw, an attacker who has legitimate access can leverage the vulnerabilities to alter critical settings and functionalities, posing significant risks to system integrity and user data security. Immediate actions to rectify permissions are essential to mitigate these risks and enhance the overall security posture of the application.

Affected Version(s)

Endpoint Manager Mobile 12.1.0.4

Endpoint Manager Mobile 12.1.0.4

Endpoint Manager Mobile 12.0.0.5

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.