Vulnerability Details CVE-2023-28129
DSM 2022.2 SU2 and all prior versions allows a local low privileged account to execute arbitrary OS commands as the DSM software installation user.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 42.2%
CVSS Severity
CVSS v3 Score 7.8
Products affected by CVE-2023-28129
-
cpe:2.3:a:ivanti:desktop_&_server_management:*
-
cpe:2.3:a:ivanti:desktop_&_server_management:2022.2