CVE-2023-46260: Critical severity ivanti avalanche vulnerability
Published Dec 19, 2023
·Updated
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
Affected Software
2 affected components
All of the following
Ivanti Avalanche<6.4.2
Microsoft Windows
Event History
Dec 19, 2023
CVE Published
03:43 PM
Data Sourced
03:43 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2023-46260?
CVE-2023-46260 has a high severity rating due to the potential for Denial of Service and code execution.
2
How do I fix CVE-2023-46260?
To fix CVE-2023-46260, update your Ivanti Avalanche software to version 6.4.2 or later.
3
What type of attack is associated with CVE-2023-46260?
CVE-2023-46260 is associated with remote code execution and Denial of Service attacks through specially crafted data packets.
4
Which software is affected by CVE-2023-46260?
CVE-2023-46260 affects Ivanti Avalanche software versions prior to 6.4.2.
5
Can CVE-2023-46260 be exploited remotely?
Yes, CVE-2023-46260 can be exploited remotely by an attacker who sends malicious data packets to the Mobile Device Server.