CVE-2023-28125: Race Condition
Published May 9, 2023
·Updated
An improper authentication vulnerability exists in Avalanche Premise versions 6.3.x and below that could allow an attacker to gain access to the server by registering to receive messages from the server and perform an authentication bypass.
Affected Software
1 affected component
Ivanti Avalanche<=6.3.4.153
Event History
May 9, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2023-28125?
CVE-2023-28125 is an improper authentication vulnerability in Avalanche Premise versions 6.3.x and below.
2
How does the CVE-2023-28125 vulnerability occur?
The CVE-2023-28125 vulnerability occurs due to improper authentication in Avalanche Premise.
3
What could an attacker do with CVE-2023-28125?
An attacker could gain access to the server by registering to receive messages and perform an authentication bypass.
4
What is the severity of CVE-2023-28125?
The severity of CVE-2023-28125 is medium, with a CVSS score of 5.9.
5
How to fix the CVE-2023-28125 vulnerability?
To fix the CVE-2023-28125 vulnerability, it is recommended to upgrade Avalanche Premise to a version higher than 6.3.4.153.