Record summary

CVE-2023-46808 has a selected CVSS score of 9.9 (critical).

Description

An file upload vulnerability in Ivanti ITSM before 2023.4, allows an authenticated remote user to perform file writes to the server. Successful exploitation may lead to execution of commands in the context of non-root user.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · May 14, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 24, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List2023.3 to ≤ 2023.3affected

Default status: unaffected

VulnCheck, CVE ListBefore 2023.4affected

References

2