CVE-2024-36131
HIGHEPMM <12.1.0.1 - Command Injection
Title source: llmDescription
An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary commands on the underlying operating system of the appliance.
Scores
CVSS v3
8.8
EPSS
0.0313
EPSS Percentile
86.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (1)
ivanti/endpoint_manager_mobile
< 12.1.0.1
Timeline
Published
Aug 07, 2024
Tracked Since
Feb 18, 2026