CVE-2023-28128
58Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 7.2epss 85%
from disclosure to weapon0 days
Published on NVDMay 9
metasploitApr 24
exploitation probability
85%top 1% of all CVEs
observed exploitation
nono source reports it
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · Avalanche