Vulnerability CVE-2023-28126


Published: 2023-05-09   Modified: 2023-05-10

Description:
An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain access by exploiting the SetUser method or can exploit the Race Condition in the authentication message.

 References:
https://forums.ivanti.com/s/article/ZDI-CAN-17750-Ivanti-Avalanche-EnterpriseServer-GetSettings-Exposed-Dangerous-Method-Authentication-Bypass-Vulnerability?language=en_US

Copyright 2026, cxsecurity.com

 

Back to Top