PT-2023-5493 · Ivanti · Ivanti Avalanche
Published
2023-08-10
·
Updated
2023-08-16
·
CVE-2023-32561
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Ivanti Avalanche versions prior to 6.4.1
Description
A previously generated artifact by an administrator could be accessed by an attacker, potentially leading to authentication bypass. The vulnerability is related to errors during the authentication procedure in the Ivanti Avalanche mobile device management system. Exploitation of this issue could allow a remote attacker to elevate their privileges.
Recommendations
For versions prior to 6.4.1, update to version 6.4.1 to resolve the issue. As a temporary workaround, consider restricting access to the
dumpHeap method to minimize the risk of exploitation.Fix
Improper Authentication
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ivanti Avalanche