7.8

CVE-2023-28129

DSM 2022.2 SU2 and all prior versions allows a local low privileged account to execute arbitrary OS commands as the DSM software installation user.

Data is provided by the National Vulnerability Database (NVD)
IvantiDesktop & Server Management Version < 2022.2
IvantiDesktop & Server Management Version2022.2 Update-
IvantiDesktop & Server Management Version2022.2 Updatesu1
IvantiDesktop & Server Management Version2022.2 Updatesu2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.2% 0.422
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H