First published: Thu Aug 10 2023(Updated: )
An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code execution. Thanks to a Researcher at Tenable for finding and reporting. Fixed in version 6.4.1.
Credit: Robel Campbell support@hackerone.com support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti Avalanche | <6.4.1 | |
Ivanti Avalanche | =6.4.2.313 | |
Ivanti Avalanche | =6.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-32560.
The severity of CVE-2023-32560 is critical, with a severity value of 9.8.
An attacker can exploit the CVE-2023-32560 vulnerability by sending a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code execution.
The Ivanti Avalanche software versions up to and excluding 6.4.1 are affected by CVE-2023-32560.
CVE-2023-32560 can be fixed by updating to version 6.4.1 of Ivanti Avalanche.