← Back to browse · API

CVE-2023-28126

Severity
MEDIUM
CVSS
5.9
EPSS
0.66659
Risk score
46.93
CISA KEV
No
PoC
No
Published
2023-05-09
Modified
2025-01-29
First seen
2026-08-07
Aliases
EUVD-2023-31837, GHSA-9MHQ-XCRQ-XC75
Products
Ivanti:Avalanche Avalanche versions 6.3.x and below
Sources
euvd EUVD-2023-31837

Description

An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain access by exploiting the SetUser method or can exploit the Race Condition in the authentication message.

References