First published: Tue May 09 2023(Updated: )
An improper authentication vulnerability exists in Avalanche Premise versions 6.3.x and below that could allow an attacker to gain access to the server by registering to receive messages from the server and perform an authentication bypass.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti Avalanche | <=6.3.4.153 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-28125 is an improper authentication vulnerability in Avalanche Premise versions 6.3.x and below.
The CVE-2023-28125 vulnerability occurs due to improper authentication in Avalanche Premise.
An attacker could gain access to the server by registering to receive messages and perform an authentication bypass.
The severity of CVE-2023-28125 is medium, with a CVSS score of 5.9.
To fix the CVE-2023-28125 vulnerability, it is recommended to upgrade Avalanche Premise to a version higher than 6.3.4.153.