ZeroHour

CVE-2023-28126

CVSS 3.1
5.9 medium
EPSS
67%p99
Published
()
Modified
Description

An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain access by exploiting the SetUser method or can exploit the Race Condition in the authentication message.

Vendors
ivanti
Products
avalanche
Weakness
CWE-305, CWE-362
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.