ZeroHour

CVE-2020-13772

PoC
CVSS 3.1
5.3 medium
EPSS
2%p82
Published
()
Modified
Description

In /ldclient/ldprov.cgi in Ivanti Endpoint Manager through 2020.1.1, an attacker is able to disclose information about the server operating system, local pathnames, and environment variables with no authentication required.

Vendors
ivanti
Products
endpoint manager
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.