|
|||
Rule General Information |
---|
Release Date: | 2025-03-11 | |
Rule Name: | Ivanti Avalanche Remote Control Server validateAMCWSConnection SSRF Vulnerability (CVE-2023-46262) | |
Severity: | High | |
CVE ID: | CVE-2023-46262 | |
Rule Protection Details |
---|
Description: | An unauthenticated attacked could send a specifically crafted web request causing a Server-Side Request Forgery (SSRF) in Ivanti Avalanche Remote Control server. | |
Impact: | SSRF is a security vulnerability constructed by an attacker to form a request initiated by a server. By exploiting this vulnerability, an attacker can bypass access restrictions such as firewalls, thereby using an infected or vulnerable server as a proxy for port scanning and even accessing internal system data. | |
Affected OS: | Windows, Linux, Others | |
Reference: | https://download.wavelink.com/Files/avalanche_v6.4.2_release_notes.txt |
|
Solutions |
---|
Please refer to announcements or patches release by the vendor: https://download.wavelink.com/Files/avalanche_v6.4.2_release_notes.txt |