PT-2023-8010 · Ivanti · Ivanti Avalanche Enterpriseserver Service

Published

2023-05-30

·

Updated

2024-09-05

·

CVE-2023-41725

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ivanti Avalanche EnterpriseServer Service (affected versions not specified)
Description The issue is related to an unrestricted file upload vulnerability in the Ivanti Avalanche EnterpriseServer Service, which can be exploited to elevate privileges and execute arbitrary code in the context of SYSTEM. This vulnerability is associated with the saveConfig method of the mobile device management system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Unrestricted File Upload

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

BDU:2023-09125
CVE-2023-41725
ZDI-23-1800

Affected Products

Ivanti Avalanche Enterpriseserver Service