PT-2023-5493 · Ivanti · Ivanti Avalanche

Published

2023-08-10

·

Updated

2023-08-16

·

CVE-2023-32561

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Ivanti Avalanche versions prior to 6.4.1
Description A previously generated artifact by an administrator could be accessed by an attacker, potentially leading to authentication bypass. The vulnerability is related to errors during the authentication procedure in the Ivanti Avalanche mobile device management system. Exploitation of this issue could allow a remote attacker to elevate their privileges.
Recommendations For versions prior to 6.4.1, update to version 6.4.1 to resolve the issue. As a temporary workaround, consider restricting access to the dumpHeap method to minimize the risk of exploitation.

Fix

Improper Authentication

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-06139
CVE-2023-32561
ZDI-23-1116

Affected Products

Ivanti Avalanche