CVE-2023-46221
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Dec 19, 2023
Updated: Dec 21, 2023
CWE ID 787
Summary
CVE-2023-46221 is a vulnerability affecting the Mobile Device Server that allows an attacker to send maliciously crafted data packets. This issue can lead to memory corruption, resulting in a Denial of Service (DoS) attack or potentially code execution. An attacker could exploit this vulnerability to disrupt the server's functionality or gain unauthorized access. The precise method of exploitation requires further investigation, but organizations using the affected Mobile Device Server are advised to apply the necessary patches promptly to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Ivanti Avalanche
Affected Vendors
- Ivanti Software Inc.