← Back

CVE-2023-28126

nvd nist
Published: May 9, 2023Modified: Jan 29, 2025

JSON object

Loading...
5.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.2 / Impact: 3.6
Source: NVD

Description

An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain access by exploiting the SetUser method or can exploit the Race Condition in the authentication message.

Affected (1)

Products: Ivanti: Avalanche
1 product
Avalanche
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 6.3.4.153

Timeline

No history available yet.