CVE-2021-3198

MEDIUM

Ivanti MobileIron < 10.7.0.1-9 - OS Command Injection via 'install rpm url' Command

Title source: llm
STIX 2.1

Description

By abusing the 'install rpm url' command, an attacker can escape the restricted clish shell on affected versions of Ivanti MobileIron Core. This issue was fixed in version 11.1.0.0.

Scores

CVSS v3 6.5
EPSS 0.0220
EPSS Percentile 84.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-78
Status published
Products (1)
ivanti/mobileiron < 10.7.0.1-9
Published Jul 22, 2021
Tracked Since Feb 18, 2026