VYPR
Critical severity9.8NVD Advisory· Published Oct 18, 2023· Updated Jun 17, 2026

CVE-2023-35084

CVE-2023-35084

Description

Unsafe Deserialization of User Input could lead to Execution of Unauthorized Operations in Ivanti Endpoint Manager 2022 su3 and all previous versions, which could allow an attacker to execute commands remotely.

Affected products

7
  • cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*:*range: <2022
    • cpe:2.3:a:ivanti:endpoint_manager:2022:-:*:*:*:*:*:*
    • cpe:2.3:a:ivanti:endpoint_manager:2022:su1:*:*:*:*:*:*
    • cpe:2.3:a:ivanti:endpoint_manager:2022:su2:*:*:*:*:*:*
    • cpe:2.3:a:ivanti:endpoint_manager:2022:su3:*:*:*:*:*:*
    • (no CPE)range: 2022 su3 and all previous versions
  • Range: 2022 su3

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.