SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-35083

Allows an authenticated attacker with network access to read arbitrary files on Endpoint Manager recently discovered on 2022 SU3 and all previous versions potentially leading to the leakage of sensitive information.

MEDIUM 6.5EPSS 1.09%

Does this matter?

Lower severity and a low EPSS score (1.09%). Track it; it rarely justifies an emergency change on its own.

Description

Allows an authenticated attacker with network access to read arbitrary files on Endpoint Manager recently discovered on 2022 SU3 and all previous versions potentially leading to the leakage of sensitive information.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
1.09% probability · 63th percentile
CISA KEV
Not listed
Affected
ivanti/endpoint manager
Source
support@hackerone.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.