CVE-2023-46217: Critical severity ivanti avalanche vulnerability
Published Dec 19, 2023
·Updated
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
Affected Software
2 affected components
All of the following
Ivanti Avalanche<6.4.2
Microsoft Windows
Event History
Dec 19, 2023
CVE Published
03:43 PM
Data Sourced
03:43 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2023-46217?
CVE-2023-46217 is classified as a critical vulnerability that can lead to Denial of Service or potential code execution.
2
How do I fix CVE-2023-46217?
To fix CVE-2023-46217, upgrade Ivanti Avalanche to the latest version beyond 6.4.2.
3
What software is affected by CVE-2023-46217?
CVE-2023-46217 specifically affects Ivanti Avalanche versions up to 6.4.2.
4
Can CVE-2023-46217 lead to remote code execution?
Yes, CVE-2023-46217 can potentially allow an attacker to execute arbitrary code on the affected server.
5
What type of attack does CVE-2023-46217 facilitate?
CVE-2023-46217 facilitates an attack that involves sending specially crafted data packets to the Mobile Device Server.