CVE-2019-12376

medium

Description

Use of a hard-coded encryption key in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to full managed endpoint compromise by an authenticated user with read privileges.

References

https://www.gnzlabs.io/gnzlabs-blog/landesk-management-server-hard-coded-encryption-key/

Details

Source: Mitre, NVD

Published: 2019-06-03

Updated: 2026-06-17

Risk Information

CVSS v2

Base Score: 2.7

Vector: CVSS2#AV:A/AC:L/Au:S/C:P/I:N/A:N

Severity: Low

CVSS v3

Base Score: 4.5

Vector: CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Severity: Medium

EPSS

EPSS: 0.00029