← back
CVE-2023-32560highCWE-20CWE-787

CVE-2023-32560

78Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 8.8epss 99%
from disclosure to weapon7 days
Published on NVDAug 10
1st PoC+7d
metasploit+4d
exploitation probability
99%top 1% of all CVEs
observed exploitation
nono source reports it
5 public exploit(s)
In short

Wavelink Avalanche Manager has a flaw where specially crafted messages can crash the service or allow attackers to run unauthorized code on the system. This is dangerous because it affects a management tool that controls critical infrastructure.

Technical detail

The vulnerability stems from improper input validation (CWE-20) and a buffer overflow (CWE-787) in the Wavelink Avalanche Manager message handling. An attacker can send a malicious message to trigger denial of service or achieve remote code execution. The flaw was patched in version 6.4.1.

Summary generated and translated by AI from the official description.
An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code execution. Thanks to a Researcher at Tenable for finding and reporting. Fixed in version 6.4.1.
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Ivanti · Avalanche
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.