CVE-2018-6316
Last modified
CVE-2018-6316 is a vulnerability of currently unknown severity. Ivanti Endpoint Security (formerly HEAT Endpoint Management and Security Suite) 8.5 Update 1 and earlier allows an authenticated user with low privileges and access to the local network to bypass application whitelisting when using the Application Control module on Ivanti Endpoint Security in lockdown mode.. EPSS estimates a 1.90% chance of exploitation in the next 30 days.
Description
Ivanti Endpoint Security (formerly HEAT Endpoint Management and Security Suite) 8.5 Update 1 and earlier allows an authenticated user with low privileges and access to the local network to bypass application whitelisting when using the Application Control module on Ivanti Endpoint Security in lockdown mode.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Ivanti | Endpoint Security | <= 8.5 | — |
| Ivanti | Endpoint Security | 8.5 | Update 1 |
References
- https://community.ivanti.com/docs/DOC-65656Permissions Required
- https://community.ivanti.com/docs/DOC-65656Permissions Required
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-6316?
How severe is CVE-2018-6316?
How do I fix CVE-2018-6316?
Are you affected by CVE-2018-6316?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
