CVE-2023-46223: Critical severity ivanti avalanche vulnerability
Published Dec 19, 2023
·Updated
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
Affected Software
2 affected components
All of the following
Ivanti Avalanche<6.4.2
Microsoft Windows
Event History
Dec 19, 2023
CVE Published
via MITRE·03:43 PM
Data Sourced
via MITRE·03:43 PM
DescriptionSeverity
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-46223?
CVE-2023-46223 is considered a critical vulnerability due to its potential for Denial of Service (DoS) or code execution.
2
How do I fix CVE-2023-46223?
To mitigate CVE-2023-46223, update your Ivanti Avalanche software to version 6.4.2 or later.
3
What type of attack is associated with CVE-2023-46223?
CVE-2023-46223 is associated with attackers sending specially crafted data packets to the Mobile Device Server.
4
What is the result of exploiting CVE-2023-46223?
Exploiting CVE-2023-46223 can lead to memory corruption, potentially resulting in Denial of Service or code execution.
5
Which software versions are affected by CVE-2023-46223?
CVE-2023-46223 affects Ivanti Avalanche versions prior to 6.4.2.