CVE-2023-28324: Input Validation
Published Jun 30, 2023
·Updated
A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege escalation or remote code execution.
Affected Software
1 affected component
Ivanti Endpoint Manager<=2022
Event History
Jun 30, 2023
CVE Published
via MITRE·11:40 PM
Data Sourced
via MITRE·11:40 PM
Description
Frequently Asked Questions
1
What is CVE-2023-28324?
CVE-2023-28324 is an improper input validation vulnerability in Ivanti Endpoint Manager 2022 and below that could allow privilege escalation or remote code execution.
2
How severe is CVE-2023-28324?
CVE-2023-28324 has a severity rating of 9.8 (critical).
3
What software versions are affected by CVE-2023-28324?
Ivanti Endpoint Manager 2022 and below are affected by CVE-2023-28324.
4
How can CVE-2023-28324 be exploited?
CVE-2023-28324 can be exploited to achieve privilege escalation or remote code execution.
5
Is there a fix available for CVE-2023-28324?
It is recommended to update Ivanti Endpoint Manager to a version that is not affected by CVE-2023-28324.