APP: Ivanti Avalanche EnterpriseServer Service Authentication Bypass
This signature detects attempts to exploit a known vulnerability against Ivanti Avalanche EnterpriseServer Service. A successful attack can lead to security bypass.
Extended Description
An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 using inforail Service allows Privilege Escalation via Enterprise Server Service.
Affected Products
Ivanti avalanche
References
CVE: CVE-2023-28126
URL: http://www.zerodayinitiative.com/advisories/ZDI-21-1324/ http://www.zerodayinitiative.com/advisories/ZDI-22-785/ https://download.wavelink.com/Files/avalanche_v6.3.4_release_notes.txt http://www.zerodayinitiative.com/advisories/ZDI-23-454/ https://download.wavelink.com/Files/avalanche_v6.4.0_release_notes.txt
srx-branch-19.3
vsrx3bsd-19.2
srx-19.4
vsrx3bsd-19.4
srx-branch-19.4
vsrx-19.4
vsrx-19.2
srx-19.3
Ivanti
7.5