First published: Thu Aug 10 2023(Updated: )
An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. Fixed in version 6.4.1.
Credit: support@hackerone.com support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti Avalanche | <6.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-32565 is a vulnerability that allows an attacker to send a specially crafted request which can lead to leakage of sensitive data or a resource-based DoS attack.
CVE-2023-32565 is classified as critical with a severity rating of 9.1.
Versions up to and exclusive of 6.4.1 of Ivanti Avalanche are affected by CVE-2023-32565.
CVE-2023-32565 has been fixed in version 6.4.1 of Ivanti Avalanche. It is recommended to update to this version to mitigate the vulnerability.
More information about CVE-2023-32565 can be found at the following reference link: [Ivanti Avalanche Vulnerabilities Addressed in 6.4.1](https://forums.ivanti.com/s/article/Avalanche-Vulnerabilities-Addressed-in-6-4-1?language=en_US).