forums.ivanti.com
https://forums.ivanti.com/s/article/SA-CVE-2023-46808-Authenticated-Remote-File-Write-for-Ivanti-Neurons-for-ITSM CVE-2023-46808
CRITICAL
Ivanti neurons_for_itsm Unrestricted Upload of File with Dangerous Type
Record summary
CVE-2023-46808 has a selected CVSS score of 9.9 (critical).
Description
An file upload vulnerability in Ivanti ITSM before 2023.4, allows an authenticated remote user to perform file writes to the server. Successful exploitation may lead to execution of commands in the context of non-root user.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · May 14, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 24, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | 2023.3 to ≤ 2023.3 | affected |
neurons_for_itsmBrowse Ivanti / neurons_for_itsmDefault status: unaffected | VulnCheck, CVE List | Before 2023.4 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-46808