← Back

CVE-2021-3540

nvd nist
Published: Jul 22, 2021Modified: Nov 21, 2024

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD

Description

By abusing the 'install rpm info detail' command, an attacker can escape the restricted clish shell on affected versions of Ivanti MobileIron Core. This issue was fixed in version 11.1.0.0.

Affected (2)

Products: Ivanti: Mobileiron
1 product
Mobileiron
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Ivanti
Up to 10.7.0.1-9
From 11.0.0.0 to 11.1.0.0

Timeline

No history available yet.