PT-2023-8010 · Ivanti · Ivanti Avalanche Enterpriseserver Service

CVE-2023-41725

·

Publicado

2023-05-30

·

Atualizado

2024-09-05

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ivanti Avalanche EnterpriseServer Service (affected versions not specified)
Description The issue is related to an unrestricted file upload vulnerability in the Ivanti Avalanche EnterpriseServer Service, which can be exploited to elevate privileges and execute arbitrary code in the context of SYSTEM. This vulnerability is associated with the saveConfig method of the mobile device management system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Unrestricted File Upload

Incorrect Privilege Assignment

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-09125
CVE-2023-41725
ZDI-23-1800

Produtos afetados

Ivanti Avalanche Enterpriseserver Service