PT-2023-5493 · Ivanti · Ivanti Avalanche

Publicado

2023-08-10

·

Atualizado

2023-08-16

·

CVE-2023-32561

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Ivanti Avalanche versions prior to 6.4.1
Description A previously generated artifact by an administrator could be accessed by an attacker, potentially leading to authentication bypass. The vulnerability is related to errors during the authentication procedure in the Ivanti Avalanche mobile device management system. Exploitation of this issue could allow a remote attacker to elevate their privileges.
Recommendations For versions prior to 6.4.1, update to version 6.4.1 to resolve the issue. As a temporary workaround, consider restricting access to the dumpHeap method to minimize the risk of exploitation.

Correção

Improper Authentication

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-06139
CVE-2023-32561
ZDI-23-1116

Produtos afetados

Ivanti Avalanche