CVE-2023-28126: Race Condition
Published May 9, 2023
·Updated
An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain access by exploiting the SetUser method or can exploit the Race Condition in the authentication message.
Affected Software
1 affected component
Ivanti Avalanche<=6.3.4.153
Event History
May 9, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2023-28126?
CVE-2023-28126 is an authentication bypass vulnerability in Avalanche versions 6.3.x and below.
2
How can an attacker exploit CVE-2023-28126?
An attacker can exploit CVE-2023-28126 by exploiting the SetUser method or by exploiting the Race Condition in the authentication message.
3
What is the severity of CVE-2023-28126?
CVE-2023-28126 has a severity rating of medium and a CVSS score of 5.9.
4
Which software versions are affected by CVE-2023-28126?
Avalanche versions 6.3.x and below are affected by CVE-2023-28126.
5
Is there a fix available for CVE-2023-28126?
Currently, there is no information regarding a fix for CVE-2023-28126. It is recommended to follow the vendor's security advisory for updates.