CVE-2023-46262: SSRF
Published Dec 19, 2023
·Updated
An unauthenticated attacked could send a specifically crafted web request causing a Server-Side Request Forgery (SSRF) in Ivanti Avalanche Remote Control server.
Affected Software
1 affected component
Ivanti Avalanche<=6.4.1
Event History
Dec 19, 2023
CVE Published
03:43 PM
Data Sourced
03:43 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2023-46262?
CVE-2023-46262 is classified as a high severity vulnerability due to its potential for unauthenticated exploitation.
2
How do I fix CVE-2023-46262?
To remediate CVE-2023-46262, upgrade Ivanti Avalanche to version 6.4.2 or later.
3
What impact does CVE-2023-46262 have on affected systems?
CVE-2023-46262 allows an unauthenticated attacker to perform Server-Side Request Forgery, which can lead to unauthorized access and data exposure.
4
Which versions of Ivanti Avalanche are affected by CVE-2023-46262?
Ivanti Avalanche versions up to and including 6.4.1 are affected by CVE-2023-46262.
5
Is there a workaround for CVE-2023-46262 if immediate patching is not possible?
There are no officially recommended workarounds for CVE-2023-46262, so prompt upgrading is essential.