CVE-2023-46262
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2023-46262 is a newly discovered vulnerability affecting Ivanti Avalanche Remote Control servers. An unauthenticated attacker can exploit this issue by crafting a malicious web request, resulting in a Server-Side Request Forgery (SSRF). This SSRF vulnerability allows the attacker to gain unauthorized access to internal resources, potentially leading to data theft or server manipulation. Ivanti Avalanche Remote Control users are advised to apply the necessary patches as soon as possible to mitigate this risk. The successful exploitation of this vulnerability can lead to significant security implications, including data breaches and server compromise.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Ivanti Avalanche
Affected Vendors
- Ivanti Software Inc.