The Ivanti EPMM server must be maintained at a supported version.
Overview
| Finding ID | Version | Rule ID | IA Controls | Severity |
| V-251418 | IMIC-11-010800 | SV-251418r1004745_rule | CCI-002605 | high |
| Description | ||||
| The UEM vendor maintains specific product versions for a specific period of time. MDM/EMM server versions no longer supported by the vendor will not receive security updates for new vulnerabilities, which leaves them subject to exploitation. Satisfies: FPT_TUD_EXT.1.1, FPT_TUD_EXT.1.2 Reference: PP-MDM-414005 | ||||
| STIG | Date | |||
| Ivanti EPMM Server Security Technical Implementation Guide | 2024-07-30 | |||
Details
Check Text (C-251418r1004745_chk)
Verify the Core server version is a supported version. This requirement is Not Applicable for the cloud version of Core.
Find the list of currently supported on-prem versions of Core server here: https://help.ivanti.com/mi/help/en_us/EML/3.16.1/rni/Content/EmailPlusiOSReleaseNotes/Support_and_compatibilit.htm
Log onto the Core console and determine the installed version of Core:
1. Click on the round person icon in the top right corner of the Core console.
2. In the drop-down menu, select "About".
3. View the version of Core that is installed.
4. Verify the version is a supported version.
If the installed version of the Core server is not a supported version, this is a finding.
Fix Text (F-54806r806385_fix)
Update Core to the most current version. If using the cloud version of Core, this requirement is automatically met.