First published: Fri Jun 30 2023(Updated: )
A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege escalation or remote code execution.
Credit: support@hackerone.com support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti Endpoint Manager | <=2022 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-28324 is an improper input validation vulnerability in Ivanti Endpoint Manager 2022 and below that could allow privilege escalation or remote code execution.
CVE-2023-28324 has a severity rating of 9.8 (critical).
Ivanti Endpoint Manager 2022 and below are affected by CVE-2023-28324.
CVE-2023-28324 can be exploited to achieve privilege escalation or remote code execution.
It is recommended to update Ivanti Endpoint Manager to a version that is not affected by CVE-2023-28324.