CVE-2023-46222: Critical severity ivanti avalanche vulnerability
Published Dec 19, 2023
·Updated
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
Affected Software
2 affected components
All of the following
Ivanti Avalanche<6.4.2
Microsoft Windows
Event History
Dec 19, 2023
CVE Published
03:43 PM
Data Sourced
03:43 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2023-46222?
CVE-2023-46222 has been categorized as a critical vulnerability due to its potential to cause memory corruption leading to Denial of Service or code execution.
2
How do I fix CVE-2023-46222?
To remediate CVE-2023-46222, it is recommended to update to Ivanti Avalanche version 6.4.2 or later.
3
What types of attacks can CVE-2023-46222 be exploited for?
CVE-2023-46222 can be exploited to perform Denial of Service attacks or execute arbitrary code remotely.
4
Which software is affected by CVE-2023-46222?
CVE-2023-46222 affects Ivanti Avalanche versions prior to 6.4.2.
5
Is Microsoft Windows affected by CVE-2023-46222?
No, Microsoft Windows is not affected by CVE-2023-46222.