Record summary

CVE-2023-32563 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

An unauthenticated attacker could achieve the code execution through a RemoteControl server.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 16, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 9, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: affected

CVE List, VulnCheck6.4.1 to < 6.4.1unaffected

Nuclei templates

1
ProjectDiscoveryCRITICALIvanti Avalanche - Remote Code ExecutionCVSS 9.8

An unauthenticated attacker could achieve the code execution through a RemoteControl server.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.

Remediation

Apply the latest security patches or updates provided by Ivanti to mitigate this vulnerability.

WeaknessesCWE-22
Authorsprincechaddha
Template tagscvecve2023ivantiavalancherceoastunauthintrusivevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:ivanti:avalanche:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3