NA

CVE-2023-38344

Published: 21/09/2023 Updated: 25/09/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

An issue exists in Ivanti Endpoint Manager prior to 2022 SU4. A file disclosure vulnerability exists in the GetFileContents SOAP action exposed via /landesk/managementsuite/core/core.secure/OsdScript.asmx. The application does not sufficiently restrict user-supplied paths, allowing for an authenticated malicious user to read arbitrary files from a remote system, including the private key used to authenticate to agents for remote access.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ivanti endpoint manager 2022

ivanti endpoint manager