| |
Vulnerability CVE-2018-6316
Published: 2018-02-15 Modified: 2018-02-16
Description: |
Ivanti Endpoint Security (formerly HEAT Endpoint Management and Security Suite) 8.5 Update 1 and earlier allows an authenticated user with low privileges and access to the local network to bypass application whitelisting when using the Application Control module on Ivanti Endpoint Security in lockdown mode. |
Type:
CWE-863 (Incorrect Authorization)
CVSS2 => (AV:N/AC:M/Au:S/C:P/I:P/A:P)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
6/10 |
6.4/10 |
6.8/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Medium |
Single time |
Confidentiality impact |
Integrity impact |
Availability impact |
Partial |
Partial |
Partial |
References: |
https://community.ivanti.com/docs/DOC-65656
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|