Lucene search

K
cveHackeroneCVE-2023-46803
HistoryDec 19, 2023 - 4:15 p.m.

CVE-2023-46803

2023-12-1916:15:11
CWE-787
hackerone
web.nvd.nist.gov
21
cve-2023-46803
attack
data packets
memory corruption
dos
mobile device server

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.004

Percentile

73.9%

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS).

Affected configurations

Nvd
Vulners
Node
ivantiavalancheRange<6.4.2premise
AND
microsoftwindowsMatch-
VendorProductVersionCPE
ivantiavalanche*cpe:2.3:a:ivanti:avalanche:*:*:*:*:premise:*:*:*
microsoftwindows-cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "vendor": "Ivanti",
    "product": "Avalanche",
    "versions": [
      {
        "version": "6.4.1",
        "status": "affected",
        "lessThanOrEqual": "6.4.1",
        "versionType": "semver"
      }
    ]
  }
]

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.004

Percentile

73.9%

Related for CVE-2023-46803