Тёмный
No video :(

Finding a three 0-day exploit chain in Ivanti EPMM and Ivanti Sentry - Tor E. Bjørstad 

NDC Conferences
Подписаться 196 тыс.
Просмотров 666
50% 1

This talk was recorded at NDC Security in Oslo, Norway. #ndcsecurity #ndcconferences #security #developer #softwaredeveloper
Attend the next NDC conference near you:
ndcconferences...
ndc-security.com/
Subscribe to our RU-vid channel and learn every day:
/‪@NDC‬
Follow our Social Media!
/ ndcconferences
/ ndc_conferences
/ ndc_conferences
During the summer of 2023, a team at mnemonic discovered three 0-day vulnerabilities in Ivanti Endpoint Protection Manager Mobile (EPMM, formerly known as Mobileiron Core) and Ivanti Sentry.
- CVE-2023-35078: authentication bypass in Ivanti EPMM, CVSS 9.8
- CVE-2023-35081: path traversal / arbitrary file write in Ivanti EPMM, CVSS 7.2
- CVE-2023-38035: authentication bypass in Ivanti Sentry, CVSS 9.8, allowing command execution as root.
All three vulnerabilities are listed in CISA's Known Exploited Vulnerabilities catalog, as they are known to have been exploited by threat actors in the wild. Ivanti has also confirmed that the vulnerabilities can be combined in an exploit chain.
In this talk we'll take a closer look at what actually happened.

Опубликовано:

 

28 авг 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 1   
@kazime-3104
@kazime-3104 5 месяцев назад
Je refuse de croire que ce type n’est pas un dauphin
Далее
How I Met Your Data - Troy Hunt - NDC Sydney 2024
59:43
Woman = best friend🤣
00:31
Просмотров 3,2 млн
Woman = best friend🤣
00:31
Просмотров 3,2 млн