Fiche vulnérabilité
CVE-2023-35084 : faille critique ivanti endpoint manager (CVSS 9.8)
Description
Unsafe Deserialization of User Input could lead to Execution of Unauthorized Operations in Ivanti Endpoint Manager 2022 su3 and all previous versions, which could allow an attacker to execute commands remotely.
En bref
- Sévérité
- Critique (CVSS 9.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 18 oct. 2023
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- ivanti endpoint manager