CVE-2023-28324
CRITICALIvanti Endpoint Manager < 2022 - Improper Input Validation
Title source: ruleDescription
A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege escalation or remote code execution.
Exploits (2)
metasploit
WORKING POC
EXCELLENT
by James Horseman, Zach Hanley, Spencer McIntyre · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/ivanti_agent_portal_cmdexec.rb
Scores
CVSS v3
9.8
EPSS
0.7994
EPSS Percentile
99.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-20
Status
published
Products (1)
ivanti/endpoint_manager
< 2022
Published
Jul 01, 2023
Tracked Since
Feb 18, 2026