9.9
CVSSv3

CVE-2023-46808

Published: 31/03/2024 Updated: 01/04/2024
CVSS v3 Base Score: 9.9 | Impact Score: 6 | Exploitability Score: 3.1
VMScore: 0

Vulnerability Summary

An file upload vulnerability in Ivanti ITSM prior to 2023.4, allows an authenticated remote user to perform file writes to the server. Successful exploitation may lead to execution of commands in the context of non-root user.

Vulnerable Product Search on Vulmon Subscribe to Product

ivanti neurons for itsm

Recent Articles

Ivanti fixes critical Standalone Sentry bug reported by NATO
BleepingComputer • Sergiu Gatlan • 20 Mar 2024

Ivanti fixes critical Standalone Sentry bug reported by NATO By Sergiu Gatlan March 20, 2024 01:08 PM 0 Ivanti warned customers to immediately patch a critical severity Standalone Sentry vulnerability reported by NATO Cyber Security Centre researchers. Standalone Sentry is deployed as an organization's Kerberos Key Distribution Center Proxy (KKDCP) server or as a gatekeeper for ActiveSync-enabled Exchange and Sharepoint servers. Tracked as CVE-2023-41724, the security flaw impacts all supported ...