CVE-2021-3540
MEDIUMIvanti MobileIron Core <11.1.0.0 - RCE
Title source: llmDescription
By abusing the 'install rpm info detail' command, an attacker can escape the restricted clish shell on affected versions of Ivanti MobileIron Core. This issue was fixed in version 11.1.0.0.
Scores
CVSS v3
6.5
EPSS
0.0220
EPSS Percentile
84.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Classification
CWE
CWE-88
Status
published
Affected Products (1)
ivanti/mobileiron
< 10.7.0.1-9
Timeline
Published
Jul 22, 2021
Tracked Since
Feb 18, 2026