First published: Fri Mar 10 2023(Updated: )
An improper authentication vulnerability exists in Avalanche version 6.3.x and below allows unauthenticated attacker to modify properties on specific port.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti Avalanche | <6.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-44574 is an improper authentication vulnerability in Avalanche version 6.3.x and below that allows an unauthenticated attacker to modify properties on a specific port.
Avalanche version 6.3.x and below are affected by CVE-2022-44574.
CVE-2022-44574 has a severity rating of 7.5, which is considered high.
The CWE ID for CVE-2022-44574 is CWE-287.
Yes, a fix is available in Avalanche version 6.4.0 and above.