CVE-2023-28128
58Vexday Risk Score
Corrige pronto. Ella tiene exploit funcional público.
ssvc Attendcvss 7.2epss 85%
de la publicación al arma0 días
Publicada en NVD9 may
metasploit24 abr
probabilidad de explotación
85%top 1% de las CVE
explotación observada
noninguna fuente lo reporta
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Productos afectados
n/a · AvalancheReferencias
http://packetstormsecurity.com/files/172398/Ivanti-Avalanche-FileStoreConfig-Shell-Upload.htmlhttps://forums.ivanti.com/s/article/ZDI-CAN-17812-Ivanti-Avalanche-FileStoreConfig-Arbitrary-File-Upload-Remote-Code-Execution-Vulnerability?language=en_UShttps://packetstorm.news/files/id/172398