CVE-2023-32563
CRITICAL EXPLOITED NUCLEIIvanti Avalanche < 6.4.1 - Unauthenticated Remote Code Execution via RemoteControl Server
Title source: llmExploitation Summary
CVE-2023-32563 has been observed exploited in the wild (reported by VulnCheck KEV). A Nuclei detection template is also available.
Description
An unauthenticated attacker could achieve the code execution through a RemoteControl server.
Nuclei Templates (1)
Ivanti Avalanche - Remote Code Execution
CRITICALby princechaddha
References (2)
Core 2
Core References
Vendor Advisory
https://forums.ivanti.com/s/article/Avalanche-Vulnerabilities-Addressed-in-6-4-1?language=en_US
Various Sources
https://twitter.com/wvuuuuuuuuuuuuu/status/1694956245742923939
Scores
CVSS v3
9.8
EPSS
0.9017
EPSS Percentile
99.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
VulnCheck KEV
2023-11-16
CWE
CWE-22
Status
published
Products (1)
ivanti/avalanche
< 6.4.1
Published
Aug 10, 2023
Tracked Since
Feb 18, 2026