CVE-2023-46808: Malicious File Upload
An file upload vulnerability in Ivanti ITSM before 2023.4, allows an authenticated remote user to perform file writes to the server. Successful exploitation may lead to execution of commands in the context of non-root user.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-46808?
CVE-2023-46808 has been classified as a critical vulnerability due to its potential for remote exploitation.
How do I fix CVE-2023-46808?
To fix CVE-2023-46808, upgrade to Ivanti Neurons for ITSM version 2023.4 or later.
Who is affected by CVE-2023-46808?
CVE-2023-46808 affects users of Ivanti Neurons for ITSM versions prior to 2023.4.
What are the potential impacts of CVE-2023-46808?
Successful exploitation of CVE-2023-46808 may allow an authenticated remote user to execute commands on the server as a non-root user.
Is CVE-2023-46808 a zero-day vulnerability?
CVE-2023-46808 is not classified as a zero-day vulnerability since it has been publicly disclosed and patches are available.