CVE-2019-12373

CRITICAL

Ivanti LANDESK Management Suite <10.0.1.168 - Info Disclosure

Title source: llm
STIX 2.1

Description

Improper access control and open directories in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to remote disclosure of administrator passwords.

Scores

CVSS v3 9.0
EPSS 0.0006
EPSS Percentile 17.8%
Attack Vector ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-732
Status published
Products (1)
ivanti/landesk_management_suite 10.0.1.168 service_update_5
Published Jun 03, 2019
Tracked Since Feb 18, 2026