CVE-2023-28126
—CVSS 3.1
5.9 medium
EPSS
67%p99
Published
()
Modified
Description
An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain access by exploiting the SetUser method or can exploit the Race Condition in the authentication message.
- Vendors
- ivanti
- Products
- avalanche
- Weakness
- CWE-305, CWE-362
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.