First published: Thu Aug 10 2023(Updated: )
DSM 2022.2 SU2 and all prior versions allows a local low privileged account to execute arbitrary OS commands as the DSM software installation user.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti Desktop & Server Management | <2022.2 | |
Ivanti Desktop & Server Management | =2022.2 | |
Ivanti Desktop & Server Management | =2022.2-su1 | |
Ivanti Desktop & Server Management | =2022.2-su2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-28129 is a vulnerability in Ivanti Desktop & Server Management (DSM) that allows for the execution of arbitrary commands.
CVE-2023-28129 affects Ivanti Desktop & Server Management by enabling the execution of arbitrary commands.
CVE-2023-28129 has a severity rating of 7.8, which is considered high.
To fix the CVE-2023-28129 vulnerability, it is recommended to update Ivanti Desktop & Server Management to version 2022.2 or later.
More information about CVE-2023-28129 can be found at the following URL: https://forums.ivanti.com/s/article/SA-2023-07-26-CVE-2023-28129