PT-2024-2363 · Ivanti · Ivanti Itsm

Published

2024-03-20

·

Updated

2024-08-01

·

CVE-2023-46808

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ivanti ITSM versions prior to 2023.4
Description The issue is related to an file upload vulnerability, which allows an authenticated remote user to perform file writes to the server. This can lead to the execution of commands in the context of a non-root user. The vulnerability is associated with unlimited upload of dangerous file types, enabling an attacker to execute arbitrary commands by injecting specially crafted files.
Recommendations For versions prior to 2023.4, update to version 2023.4 or later to resolve the issue. As a temporary workaround, consider restricting file upload capabilities to minimize the risk of exploitation. Restrict access to sensitive areas of the server to prevent potential command execution.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

BDU:2024-02314
CVE-2023-46808

Affected Products

Ivanti Itsm