CVE-2023-28129
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.3%
exploitation probability
0.3%top 75% of all CVEs
observed exploitation
nono source reports it
DSM 2022.2 SU2 and all prior versions allows a local low privileged account to execute arbitrary OS commands as the DSM software installation user.
Affected products
Ivanti · Desktop & Server Management (DSM)