CVE-2023-46265: SSRF
Published Dec 19, 2023
·Updated
An unauthenticated could abuse a XXE vulnerability in the Smart Device Server to leak data or perform a Server-Side Request Forgery (SSRF).
Affected Software
1 affected component
Ivanti Avalanche<=6.4.1
Event History
Dec 19, 2023
CVE Published
03:43 PM
Data Sourced
03:43 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2023-46265?
CVE-2023-46265 is categorized as a high severity vulnerability due to its potential for data leakage and Server-Side Request Forgery.
2
How do I fix CVE-2023-46265?
To mitigate CVE-2023-46265, upgrade to Ivanti Avalanche version 6.4.2 or later.
3
What type of vulnerability is CVE-2023-46265?
CVE-2023-46265 is an XML External Entity (XXE) vulnerability that can be exploited for unauthorized data access.
4
Can CVE-2023-46265 be exploited remotely?
Yes, CVE-2023-46265 can be exploited by an unauthenticated attacker remotely.
5
What software versions are affected by CVE-2023-46265?
CVE-2023-46265 affects Ivanti Avalanche versions up to and including 6.4.1.