PT-2023-5493 · Ivanti · Ivanti Avalanche
Publicado
2023-08-10
·
Atualizado
2023-08-16
·
CVE-2023-32561
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Ivanti Avalanche versions prior to 6.4.1
Description
A previously generated artifact by an administrator could be accessed by an attacker, potentially leading to authentication bypass. The vulnerability is related to errors during the authentication procedure in the Ivanti Avalanche mobile device management system. Exploitation of this issue could allow a remote attacker to elevate their privileges.
Recommendations
For versions prior to 6.4.1, update to version 6.4.1 to resolve the issue. As a temporary workaround, consider restricting access to the
dumpHeap method to minimize the risk of exploitation.Correção
Improper Authentication
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ivanti Avalanche