First published: Sun Mar 31 2024(Updated: )
An file upload vulnerability in Ivanti ITSM before 2023.4, allows an authenticated remote user to perform file writes to the server. Successful exploitation may lead to execution of commands in the context of non-root user.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti Neurons for ITSM | <2023.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-46808 has been classified as a critical vulnerability due to its potential for remote exploitation.
To fix CVE-2023-46808, upgrade to Ivanti Neurons for ITSM version 2023.4 or later.
CVE-2023-46808 affects users of Ivanti Neurons for ITSM versions prior to 2023.4.
Successful exploitation of CVE-2023-46808 may allow an authenticated remote user to execute commands on the server as a non-root user.
CVE-2023-46808 is not classified as a zero-day vulnerability since it has been publicly disclosed and patches are available.