CVE-2023-28125

MEDIUM

Ivanti Avalanche < 6.3.4.153 - Authentication Bypass via Message Registration

Title source: llm
STIX 2.1

Description

An improper authentication vulnerability exists in Avalanche Premise versions 6.3.x and below that could allow an attacker to gain access to the server by registering to receive messages from the server and perform an authentication bypass.

Scores

CVSS v3 5.9
EPSS 0.0403
EPSS Percentile 88.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-287 CWE-362
Status published
Products (1)
ivanti/avalanche < 6.3.4.153
Published May 09, 2023
Tracked Since Feb 18, 2026