CVE-2024-7612

Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application components.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:*

History

18 Dec 2024, 18:27

Type Values Removed Values Added
First Time Ivanti
Ivanti endpoint Manager Mobile
References () https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2024-7612 - () https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2024-7612 - Vendor Advisory
CPE cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:*

17 Oct 2024, 19:15

Type Values Removed Values Added
Summary (en) Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to access or modify sensitive configuration files without proper authorization. (en) Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application components.

10 Oct 2024, 12:56

Type Values Removed Values Added
Summary
  • (es) Los permisos inseguros en Ivanti EPMM anterior a 12.1.0.4 permiten que un atacante autenticado local acceda o modifique archivos de configuración confidenciales sin la autorización adecuada.

08 Oct 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-08 17:15

Updated : 2024-12-18 18:27


NVD link : CVE-2024-7612

Mitre link : CVE-2024-7612

CVE.ORG link : CVE-2024-7612


JSON object : View

Products Affected

ivanti

  • endpoint_manager_mobile
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource