Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-28125


An improper authentication vulnerability exists in Avalanche Premise versions 6.3.x and below that could allow an attacker to gain access to the server by registering to receive messages from the server and perform an authentication bypass.


Published

2023-05-09T22:15:09.720

Last Modified

2025-01-29T15:15:14.183

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-287
  • Type: Primary
    CWE-362

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ivanti avalanche ≤ 6.3.4.153 Yes

References