High severity7.8NVD Advisory· Published Aug 10, 2023· Updated Jun 17, 2026
CVE-2023-28129
CVE-2023-28129
Description
DSM 2022.2 SU2 and all prior versions allows a local low privileged account to execute arbitrary OS commands as the DSM software installation user.
Affected products
62022 su2+ 4 more
- (no CPE)range: 2022 su2
- cpe:2.3:a:ivanti:desktop_\&_server_management:*:*:*:*:*:*:*:*range: <2022.2
- cpe:2.3:a:ivanti:desktop_\&_server_management:2022.2:-:*:*:*:*:*:*
- cpe:2.3:a:ivanti:desktop_\&_server_management:2022.2:su1:*:*:*:*:*:*
- cpe:2.3:a:ivanti:desktop_\&_server_management:2022.2:su2:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- forums.ivanti.com/s/article/SA-2023-07-26-CVE-2023-28129nvdVendor Advisory
News mentions
0No linked articles in our index yet.