Known Vulnerabilities for Avalanche by Ivanti
Listed below are 10 of the newest known vulnerabilities associated with "Avalanche" by "Ivanti".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-41726 json | Ivanti Avalanche Incorrect Default Permissions allows Local Privilege Escalation Vulnerability | 7.8 - HIGH | 2023-11-03 | 2023-11-09 |
| CVE-2023-41725 json | Ivanti Avalanche EnterpriseServer Service Unrestricted File Upload Local Privilege Escalation Vulnerability | 7.8 - HIGH | 2023-11-03 | 2023-11-09 |
| CVE-2023-41474 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.5 - MEDIUM | 2024-01-25 | 2024-01-31 |
| CVE-2023-32567 json | Ivanti Avalanche decodeToMap XML External Entity Processing. Fixed in version 6.4.1.236 | 9.8 - CRITICAL | 2023-08-10 | 2023-11-03 |
| CVE-2023-32566 json | An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-base... | 9.1 - CRITICAL | 2023-08-10 | 2023-08-15 |
| CVE-2023-32565 json | An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-base... | 9.1 - CRITICAL | 2023-08-10 | 2023-08-15 |
| CVE-2023-32564 json | An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allo... | 9.8 - CRITICAL | 2023-08-10 | 2023-08-15 |
| CVE-2023-32563 json | An unauthenticated attacker could achieve the code execution through a RemoteControl server. | 9.8 - CRITICAL | 2023-08-10 | 2023-08-28 |
| CVE-2023-32562 json | An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allo... | 9.8 - CRITICAL | 2023-08-10 | 2023-08-15 |
| CVE-2023-32561 json | A previously generated artifact by an administrator could be accessed by an attacker. The contents of this artifact could lea... | 7.5 - HIGH | 2023-08-10 | 2023-08-16 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ivanti | Avalanche | 6.2.2 | |||
| Application | Ivanti | Avalanche | 6.2 | |||
| Application | Ivanti | Avalanche | 6.1 | |||
| Application | Ivanti | Avalanche | 6.0 | |||
| Application | Ivanti | Avalanche | 5.3.1 | |||
| Application | Ivanti | Avalanche | 5.3 | |||
| Application | Ivanti | Avalanche | 4.6 |