CVE-2023-46221

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Dec 19, 2023
Updated: Dec 21, 2023
CWE ID 787

Summary

CVE-2023-46221 is a vulnerability affecting the Mobile Device Server that allows an attacker to send maliciously crafted data packets. This issue can lead to memory corruption, resulting in a Denial of Service (DoS) attack or potentially code execution. An attacker could exploit this vulnerability to disrupt the server's functionality or gain unauthorized access. The precise method of exploitation requires further investigation, but organizations using the affected Mobile Device Server are advised to apply the necessary patches promptly to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Ivanti Avalanche

Affected Vendors

  • Ivanti Software Inc.