HTTP: Ivanti Avalanche Remote Control Server RCServlet setProperty Authentication Bypass

This signature detects attempts to exploit a known vulnerability against Ivanti Avalanche Remote Control Server RCServlet. A successful attack can lead to security bypass.

Extended Description

An improper authentication vulnerability exists in Avalanche version 6.3.x and below allows unauthenticated attacker to modify properties on specific port.

Affected Products

Ivanti avalanche

Short Name
HTTP:CTS:IVNTI-AVLNCH-AUTH-BYPS
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Authentication Avalanche Bypass CVE-2022-44574 Control Ivanti RCServlet Remote Server setProperty
Release Date
03/30/2023
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3632
False Positive
Unknown
Vendors

Ivanti

Found a potential security threat?