CVE-2022-36971 is a critical deserialization of untrusted data vulnerability affecting Ivanti Avalanche 6.3.2.3490, specifically within the JwtTokenUtility class. This flaw allows remote attackers to bypass authentication and execute arbitrary code with service account privileges, earning a CVSS score of 8.8 (High) due to its network attack vector and high impact on confidentiality, integrity, and availability. Although not on the CISA KEV list, its high EPSS score and community discussion indicate significant exploitability potential. Currently, no public exploit code is available in common repositories like Metasploit or ExploitDB, and there is no indication of active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.3.2.3490, < 6.3.4CPE matchmatch criteria | cpe:2.3:a:ivanti:avalanche:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.