First published: Wed Oct 18 2023(Updated: )
Allows an authenticated attacker with network access to read arbitrary files on Endpoint Manager recently discovered on 2022 SU3 and all previous versions potentially leading to the leakage of sensitive information.
Credit: support@hackerone.com support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti Endpoint Manager | <2022 | |
Ivanti Endpoint Manager | =2022 | |
Ivanti Endpoint Manager | =2022-su1 | |
Ivanti Endpoint Manager | =2022-su2 | |
Ivanti Endpoint Manager | =2022-su3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-35083 is medium (6.5).
CVE-2023-35083 allows an authenticated attacker with network access to read arbitrary files on Endpoint Manager, potentially leading to the leakage of sensitive information.
CVE-2023-35083 affects Ivanti Endpoint Manager 2022, 2022-su1, 2022-su2, and 2022-su3.
An attacker with network access and authentication can exploit CVE-2023-35083 to read arbitrary files on Endpoint Manager.
You can find more information about CVE-2023-35083 in the [Ivanti forums](https://forums.ivanti.com/s/article/SA-2023-06-20-CVE-2023-35083?language=en_US).