Critical severity9.8NVD Advisory· Published Oct 18, 2023· Updated Jun 17, 2026
CVE-2023-35084
CVE-2023-35084
Description
Unsafe Deserialization of User Input could lead to Execution of Unauthorized Operations in Ivanti Endpoint Manager 2022 su3 and all previous versions, which could allow an attacker to execute commands remotely.
Affected products
7cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*:*range: <2022
- cpe:2.3:a:ivanti:endpoint_manager:2022:-:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2022:su1:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2022:su2:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2022:su3:*:*:*:*:*:*
- (no CPE)range: 2022 su3 and all previous versions
- Range: 2022 su3
Patches
Vulnerability mechanics
References
1- forums.ivanti.com/s/article/SA-2023-08-08-CVE-2023-35084nvdVendor Advisory
News mentions
0No linked articles in our index yet.