CVE-2022-43555 is a missing authentication vulnerability in the Ivanti Avalanche Printer Device Service, allowing for local privilege escalation. With a CVSS score of 7.8 (HIGH), an attacker with local access can exploit this with low complexity to achieve high confidentiality, integrity, and availability impacts. There is currently no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.4.1.236CPE matchmatch criteria | cpe:2.3:a:ivanti:avalanche:*:*:*:*:premise:*:*:* | ||
>= 6.4.1.236, < 6.4.1.236CPE match | cpe:2.3:a:ivanti:avalanche:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.