By abusing the 'install rpm url' command, an attacker can escape the restricted clish shell on affected versions of Ivanti MobileIron Core. This issue was fixed in version 11.1.0.0.
References
Link | Resource |
---|---|
https://www.rapid7.com/blog/post/2021/06/02/untitled-cve-2021-3198-and-cve-2021-3540-mobileiron-shell-escape-privilege-escalation-vulnerabilities/ | Exploit Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: rapid7
Published: 2021-06-02T00:00:00
Updated: 2021-07-22T18:27:20
Reserved: 2021-01-21T00:00:00
Link: CVE-2021-3198
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-07-22T19:15:09.097
Modified: 2021-08-02T19:08:57.870
Link: CVE-2021-3198
JSON object: View
Redhat Information
No data.
CWE