Home Ivanti CVE-2023-46808
Back to Ivanti

CVE-2023-46808

Ivanti Neurons for ITSM - File Upload Component

Ivanti CVSS 9.9 Updated March 18, 2026

Executive Risk Summary

"An authenticated remote file upload vulnerability in Ivanti ITSM before 2023.4 allows an attacker to write files to the server, potentially leading to command execution in the context of a non-root user. Successful exploitation may compromise data integrity and system security."

Operational Audit Arsenal

Target Type Web Application
Target Asset Ivanti ITSM File Upload Module
Standard Path Global Web Application Directory

Manual Verification Required

This is a non-Windows asset (Ivanti). Use the target asset details and official path provided above to verify your current version against the official vendor advisories listed below.

Patch Impact Forecast

Reboot Required Likely

Moderate, potential downtime for ITSM services

Internal Work Notes

CVE-2023-46808: Ivanti ITSM File Upload Vulnerability - Apply patch 2023.4 or later to prevent authenticated remote file writes and potential command execution.

Technical Intelligence & Operational Utilities • Delivered Weekly

Intelligence Sources

Related Ivanti Threats

Data compiled from NVD, MSRC, and CISA KEV Catalog. Intelligence synthesized via AI. Scripts provided for diagnostic purposes under MIT License.