First published: Tue Dec 19 2023(Updated: )
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Ivanti Avalanche | <6.4.2 | |
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-46261 is considered a high severity vulnerability due to its potential for memory corruption leading to Denial of Service or code execution.
CVE-2023-46261 affects systems running Ivanti Avalanche versions prior to 6.4.2, allowing attackers to exploit the Mobile Device Server.
To fix CVE-2023-46261, update Ivanti Avalanche to version 6.4.2 or later.
CVE-2023-46261 is associated with remote code execution and Denial of Service attacks through specially crafted data packets.
If you are running Ivanti Avalanche versions before 6.4.2, your version is vulnerable to CVE-2023-46261.