Aller au contenu

Fiche vulnérabilité

CVE-2023-35084 : faille critique ivanti endpoint manager (CVSS 9.8)

Description

Unsafe Deserialization of User Input could lead to Execution of Unauthorized Operations in Ivanti Endpoint Manager 2022 su3 and all previous versions, which could allow an attacker to execute commands remotely.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
18 oct. 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • ivanti endpoint manager

Références

Rechercher une autre vulnérabilité dans la base CVE