First published: Tue Dec 19 2023(Updated: )
An unauthenticated attacked could send a specifically crafted web request causing a Server-Side Request Forgery (SSRF) in Ivanti Avalanche Remote Control server.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti Avalanche | <=6.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-46262 is classified as a high severity vulnerability due to its potential for unauthenticated exploitation.
To remediate CVE-2023-46262, upgrade Ivanti Avalanche to version 6.4.2 or later.
CVE-2023-46262 allows an unauthenticated attacker to perform Server-Side Request Forgery, which can lead to unauthorized access and data exposure.
Ivanti Avalanche versions up to and including 6.4.1 are affected by CVE-2023-46262.
There are no officially recommended workarounds for CVE-2023-46262, so prompt upgrading is essential.