Improper Authorization Control in Ivanti Avalanche Software
CVE-2021-42126
8.8HIGH
Summary
An improper authorization control vulnerability in Ivanti Avalanche before version 6.3.3 allows an attacker with Inforail Service access to exploit the system and escalate privileges. This issue poses significant risks to the security of the affected environment, enabling unauthorized actions that could lead to data breaches or unauthorized access to sensitive information.
Affected Version(s)
Ivanti Avalanche 6.3.3
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved