CVE-2021-3540

MEDIUM

Ivanti MobileIron Core <11.1.0.0 - RCE

Title source: llm

Description

By abusing the 'install rpm info detail' command, an attacker can escape the restricted clish shell on affected versions of Ivanti MobileIron Core. This issue was fixed in version 11.1.0.0.

Scores

CVSS v3 6.5
EPSS 0.0220
EPSS Percentile 84.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

Classification

CWE
CWE-88
Status published

Affected Products (1)

ivanti/mobileiron < 10.7.0.1-9

Timeline

Published Jul 22, 2021
Tracked Since Feb 18, 2026