Описание
Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a device belonging to a restricted set of unenrolled devices, leading to information disclosure about EPMM appliance and impacting on the integrity of the newly enrolled device identity.
Уязвимые конфигурации
Конфигурация 1Версия до 12.6.1.1 (исключая)
Одно из
cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.8.0.0:*:*:*:*:*:*:*
EPSS
Процентиль: 41%
0.00509
Низкий
7.4 High
CVSS3
9.1 Critical
CVSS3
Дефекты
CWE-295
Связанные уязвимости
CVSS3: 7.4
github
3 месяца назад
Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a device belonging to a restricted set of unenrolled devices, leading to information disclosure about EPMM appliance and impacting on the integrity of the newly enrolled device identity.
EPSS
Процентиль: 41%
0.00509
Низкий
7.4 High
CVSS3
9.1 Critical
CVSS3
Дефекты
CWE-295