CVE-2023-46216 is a critical memory corruption vulnerability affecting Ivanti Avalanche and Microsoft Avalanche Mobile Device Servers. An unauthenticated attacker can exploit this flaw by sending specially crafted data packets, leading to a Denial of Service (DoS) or remote code execution. With a CVSS score of 9.8, it presents a high-severity risk due to its network-based attack vector and lack of required user interaction. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), Ivanti has released patches, and the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.4.2CPE matchmatch criteria | cpe:2.3:a:ivanti:avalanche:*:*:*:*:premise:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.