← Back to browse · API

CVE-2024-36130

Severity
CRITICAL
CVSS
9.8
EPSS
0.02253
Risk score
39.99
CISA KEV
No
PoC
No
Published
2024-08-07
Modified
2025-03-13
First seen
2026-08-07
Aliases
EUVD-2024-35891, GHSA-WW6R-JV53-52XQ
Products
Ivanti:EPMM 12.1.0.1 <12.1.0.1
Sources
euvd EUVD-2024-35891

Description

An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute arbitrary commands on the underlying operating system of the appliance.

References