CVE-2022-36980 is a critical authentication bypass vulnerability affecting Ivanti Avalanche 6.3.2.3490. The flaw, residing in the EnterpriseServer service, stems from improper locking during authentication operations, allowing remote attackers to bypass the existing authentication mechanism. With a CVSS score of 8.1 (HIGH), this vulnerability presents a significant risk, as it can lead to high impact on confidentiality, integrity, and availability without user interaction. While no public exploit code or active exploitation has been confirmed, the vulnerability has garnered notable community discussion, indicating awareness and potential interest from threat actors.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.3.2.3490, < 6.3.4CPE matchmatch criteria | cpe:2.3:a:ivanti:avalanche:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.