Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-28126


An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain access by exploiting the SetUser method or can exploit the Race Condition in the authentication message.


Published

2023-05-09T22:15:09.813

Last Modified

2025-01-29T15:15:14.370

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-305
  • Type: Primary
    CWE-362
  • Type: Secondary
    CWE-362

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ivanti avalanche ≤ 6.3.4.153 Yes

References