An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain access by exploiting the SetUser method or can exploit the Race Condition in the authentication message.
References
Configurations
History
29 Jan 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://forums.ivanti.com/s/article/ZDI-CAN-17750-Ivanti-Avalanche-EnterpriseServer-GetSettings-Exposed-Dangerous-Method-Authentication-Bypass-Vulnerability?language=en_US - Vendor Advisory |
16 May 2023, 18:24
Type | Values Removed | Values Added |
---|---|---|
First Time |
Ivanti
Ivanti avalanche |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.9 |
CWE | CWE-362 | |
CPE | cpe:2.3:a:ivanti:avalanche:*:*:*:*:premise:*:*:* | |
References | (MISC) https://forums.ivanti.com/s/article/ZDI-CAN-17750-Ivanti-Avalanche-EnterpriseServer-GetSettings-Exposed-Dangerous-Method-Authentication-Bypass-Vulnerability?language=en_US - Vendor Advisory |
09 May 2023, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-05-09 22:15
Updated : 2025-01-29 15:15
NVD link : CVE-2023-28126
Mitre link : CVE-2023-28126
JSON object : View
Products Affected
ivanti
- avalanche
CWE
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')