NA

CVE-2023-38343

Published: 21/09/2023 Updated: 25/09/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An XXE (XML external entity injection) vulnerability exists in the CSEP component of Ivanti Endpoint Manager prior to 2022 SU4. External entity references are enabled in the XML parser configuration. Exploitation of this vulnerability can lead to file disclosure or Server Side Request Forgery.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ivanti endpoint manager 2022

ivanti endpoint manager