CVE-2023-28129: High severity ivanti desktop & server management vulnerability
Published Aug 10, 2023
·Updated
DSM 2022.2 SU2 and all prior versions allows a local low privileged account to execute arbitrary OS commands as the DSM software installation user.
Affected Software
4 affected components
Ivanti Desktop \& Server Management<2022.2
Ivanti Desktop \& Server Management=2022.2
Ivanti Desktop \& Server Management=2022.2-su1
Ivanti Desktop \& Server Management=2022.2-su2
Event History
Aug 10, 2023
CVE Published
via MITRE·07:07 PM
Data Sourced
via MITRE·07:07 PM
Description
Frequently Asked Questions
1
What is CVE-2023-28129?
CVE-2023-28129 is a vulnerability in Ivanti Desktop & Server Management (DSM) that allows for the execution of arbitrary commands.
2
How does CVE-2023-28129 affect Ivanti Desktop & Server Management?
CVE-2023-28129 affects Ivanti Desktop & Server Management by enabling the execution of arbitrary commands.
3
What is the severity of CVE-2023-28129?
CVE-2023-28129 has a severity rating of 7.8, which is considered high.
4
How can the CVE-2023-28129 vulnerability be fixed?
To fix the CVE-2023-28129 vulnerability, it is recommended to update Ivanti Desktop & Server Management to version 2022.2 or later.
5
Where can I find more information about CVE-2023-28129?
More information about CVE-2023-28129 can be found at the following URL: https://forums.ivanti.com/s/article/SA-2023-07-26-CVE-2023-28129