Vulnerability Description
Use of a hard-coded encryption key in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to full managed endpoint compromise by an authenticated user with read privileges.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ivanti | Landesk Management Suite | 10.0.1.168 |
Related Weaknesses (CWE)
References
- https://www.gnzlabs.io/gnzlabs-blog/landesk-management-server-hard-coded-encryptExploitThird Party Advisory
- https://www.gnzlabs.io/gnzlabs-blog/landesk-management-server-hard-coded-encryptExploitThird Party Advisory
FAQ
What is CVE-2019-12376?
CVE-2019-12376 is a vulnerability with a CVSS score of 4.5 (MEDIUM). Use of a hard-coded encryption key in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to full managed endpoint compromise by an authenticated user wit...
How severe is CVE-2019-12376?
CVE-2019-12376 has been rated MEDIUM with a CVSS base score of 4.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-12376?
Check the references section above for vendor advisories and patch information. Affected products include: Ivanti Landesk Management Suite.