Vulnerability Description
In /ldclient/ldprov.cgi in Ivanti Endpoint Manager through 2020.1.1, an attacker is able to disclose information about the server operating system, local pathnames, and environment variables with no authentication required.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ivanti | Endpoint Manager | <= 2020.1.1 |
References
- https://forums.ivanti.com/s/Permissions RequiredVendor Advisory
- https://labs.jumpsec.com/cve-2020-13772-ivanti-uem-system-information-disclosureExploitThird Party Advisory
- https://forums.ivanti.com/s/Permissions RequiredVendor Advisory
- https://labs.jumpsec.com/cve-2020-13772-ivanti-uem-system-information-disclosureExploitThird Party Advisory
FAQ
What is CVE-2020-13772?
CVE-2020-13772 is a vulnerability with a CVSS score of 5.3 (MEDIUM). In /ldclient/ldprov.cgi in Ivanti Endpoint Manager through 2020.1.1, an attacker is able to disclose information about the server operating system, local pathnames, and environment variables with no a...
How severe is CVE-2020-13772?
CVE-2020-13772 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-13772?
Check the references section above for vendor advisories and patch information. Affected products include: Ivanti Endpoint Manager.