APP: Ivanti Avalanche WLAvalancheService.exe Type 101 Stack-Buffer Overflow

This signature detects attempts to exploit a known vulnerability against Ivanti Avalanche. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the server.

Extended Description

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

Short Name
APP:MISC:IVANTI-AVLNCHE-WLAS-BO
Severity
Major
Recommended
True
Recommended Action
Drop
Category
APP
Keywords
101 Avalanche CVE-2023-32560 CVE-2023-41727 CVE-2023-46216 CVE-2023-46217 Ivanti Overflow Stack-Buffer Type WLAvalancheService.exe
Release Date
02/08/2024
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

Sigpack Version
3784
Port
TCP/1777
False Positive
Unknown

Found a potential security threat?