Ivanti MobileIron Core clish Restricted Shell Escape via Argument Injection
Vulnerability Description
By abusing the 'install rpm info detail' command, an attacker can escape the restricted clish shell on affected versions of Ivanti MobileIron Core. This issue was fixed in version 11.1.0.0.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-3540
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- William Vu of Rapid7
More from Ivanti
View All →Affected Vendor
Ivanti
View all reports →