PT-2023-26374 · Ivanti · Ivanti Endpoint Manager

CVE-2023-38344

·

Publicado

2023-09-21

·

Atualizado

2024-09-25

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ivanti Endpoint Manager versions prior to 2022 SU4
Description A file disclosure issue exists in the GetFileContents SOAP action exposed via "/landesk/managementsuite/core/core.secure/OsdScript.asmx". The application does not sufficiently restrict user-supplied paths, allowing an authenticated attacker to read arbitrary files from a remote system, including the private key used to authenticate to agents for remote access.
Recommendations For Ivanti Endpoint Manager versions prior to 2022 SU4, update to version 2022 SU4 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/landesk/managementsuite/core/core.secure/OsdScript.asmx" endpoint and the GetFileContents SOAP action to minimize the risk of exploitation.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-38344

Produtos afetados

Ivanti Endpoint Manager