Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Ivanti MobileIron Core clish Restricted Shell Escape via OS Command Injection
Vulnerability Description
By abusing the 'install rpm url' command, an attacker can escape the restricted clish shell on affected versions of Ivanti MobileIron Core. This issue was fixed in version 11.1.0.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
Mobileiron MobileIron Core操作系统命令注入漏洞
Vulnerability Description
Mobileiron MobileIron Core是美国思可信(Mobileiron)公司的一款MobileIron平台的管理控制台组件。该产品支持为设备、应用程序和内容定义安全和管理策略。 Ivanti MobileIron Core 10.7.0.1-9 版本和 11.0.0.1-3版本存在操作系统命令注入漏洞,攻击者可以利用此漏洞对受影响的设备进行完全的根级控制。
CVSS Information
N/A
Vulnerability Type
N/A