« Volver al listado

CVE-2023-28129

Estado: ModificadaAlta (7.8)—

DSM 2022.2 SU2 and all prior versions allows a local low privileged account to execute arbitrary OS commands as the DSM software installation user.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-28129",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-28129",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-10-09T19:30:58.418466Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "support@hackerone.com",
      "affectedData": [
        {
          "vendor": "Ivanti",
          "product": "Desktop & Server Management (DSM) ",
          "versions": [
            {
              "status": "unaffected",
              "version": "2022 su2",
              "lessThan": "2022 su2",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2023-08-10T20:15:09.657",
  "references": [
    {
      "url": "https://forums.ivanti.com/s/article/SA-2023-07-26-CVE-2023-28129",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "support@hackerone.com"
    },
    {
      "url": "https://forums.ivanti.com/s/article/SA-2023-07-26-CVE-2023-28129",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "DSM 2022.2 SU2 and all prior versions allows a local low privileged account to execute arbitrary OS commands as the DSM software installation user."
    }
  ],
  "lastModified": "2026-06-17T05:46:56.470",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ivanti:desktop_\\&_server_management:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FBF00DFF-E7C5-4391-BEE1-16C478D224C7",
              "versionEndExcluding": "2022.2"
            },
            {
              "criteria": "cpe:2.3:a:ivanti:desktop_\\&_server_management:2022.2:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3BD5B572-B592-4203-A662-36AB51C98502"
            },
            {
              "criteria": "cpe:2.3:a:ivanti:desktop_\\&_server_management:2022.2:su1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5B8C2904-6102-4DB6-8F92-055B64EB51DB"
            },
            {
              "criteria": "cpe:2.3:a:ivanti:desktop_\\&_server_management:2022.2:su2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B8877B87-3C5D-4CAA-8A6F-738F46A19A6A"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "support@hackerone.com"
}