CVE-2018-6316
Last modified
CVE-2018-6316 is a vulnerability of currently unknown severity. Ivanti Endpoint Security (formerly HEAT Endpoint Management and Security Suite) 8.5 Update 1 and earlier allows an authenticated user with low privileges and access to the local network to bypass application whitelisting when using the Application Control module on Ivanti Endpoint Security in lockdown mode.. EPSS estimates a 1.90% chance of exploitation in the next 30 days.
Description
Ivanti Endpoint Security (formerly HEAT Endpoint Management and Security Suite) 8.5 Update 1 and earlier allows an authenticated user with low privileges and access to the local network to bypass application whitelisting when using the Application Control module on Ivanti Endpoint Security in lockdown mode.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Ivanti | Endpoint Security | <= 8.5 | — |
| Ivanti | Endpoint Security | 8.5 | Update 1 |
References
- https://community.ivanti.com/docs/DOC-65656Permissions Required
- https://community.ivanti.com/docs/DOC-65656Permissions Required
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-6316?
How severe is CVE-2018-6316?
How do I fix CVE-2018-6316?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-6307LibVNC before commit ca2a5ac02fbbadd0a21fabba779c1ea69173d10…
- CVE-2018-6308Multiple SQL injections exist in SugarCRM Community Edition …
- CVE-2018-6311One can gain root access on the Foxconn femtocell FEMTO AP-F…6.8
- CVE-2018-6312A privileged account with a weak default password on the Fox…7.2
- CVE-2018-6313Cross-site scripting (XSS) in WBCE CMS 1.3.1 allows remote a…
- CVE-2018-6315The outputSWF_TEXT_RECORD function (util/outputscript.c) in …
- CVE-2018-6317The remote management interface in Claymore Dual Miner 10.5 …
- CVE-2018-6318In Sophos Tester Tool 3.2.0.7 Beta, the driver loads (in the…
- CVE-2018-6319In Sophos Tester Tool 3.2.0.7 Beta, the driver accepts a spe…
- CVE-2018-6320A vulnerability has been discovered in login.cgi in Pulse Se…
- CVE-2018-6321Unquoted Windows search path vulnerability in the panda_url_…
- CVE-2018-6322Panda Global Protection 17.0.1 allows local users to gain pr…
Are you affected by CVE-2018-6316?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
