← Back to browse · API

CVE-2023-32560

Severity
HIGH
CVSS
8.8
EPSS
0.98919
Risk score
69.82
CISA KEV
No
PoC
No
Published
2023-08-10
Modified
2025-03-06
First seen
2026-08-07
Aliases
EUVD-2023-36804, GHSA-M39H-XJMQ-4VGF
Products
Ivanti:Avalanche patch: 6.4.1
Sources
euvd EUVD-2023-36804

Description

An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code execution. Thanks to a Researcher at Tenable for finding and reporting. Fixed in version 6.4.1.

References