forums.ivanti.com
https://forums.ivanti.com/s/article/Avalanche-Vulnerabilities-Addressed-in-6-4-1?language=en_US CVE-2023-32563
CRITICALNuclei
Ivanti avalanche Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Record summary
CVE-2023-32563 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
An unauthenticated attacker could achieve the code execution through a RemoteControl server.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 16, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 9, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
AvalancheBrowse Ivanti / AvalancheDefault status: affected | CVE List, VulnCheck | 6.4.1 to < 6.4.1 | unaffected |
Nuclei templates
1ProjectDiscoveryCRITICALIvanti Avalanche - Remote Code ExecutionCVSS 9.8
An unauthenticated attacker could achieve the code execution through a RemoteControl server.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
Remediation
Apply the latest security patches or updates provided by Ivanti to mitigate this vulnerability.
WeaknessesCWE-22
Authorsprincechaddha
Template tagscvecve2023ivantiavalancherceoastunauthintrusivevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:ivanti:avalanche:*:*:*:*:*:*:*:*
https://twitter.com/wvuuuuuuuuuuuuu/status/1694956245742923939 https://forums.ivanti.com/s/article/Avalanche-Vulnerabilities-Addressed-in-6-4-1?language=en_US https://nvd.nist.gov/vuln/detail/CVE-2023-32563 https://github.com/mayur-esh/vuln-liners
Source: ProjectDiscovery
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-32563 twitter.com
https://twitter.com/wvuuuuuuuuuuuuu/status/1694956245742923939