CVE-2023-46257

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
19/12/2023
Last modified:
06/05/2025

Description

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ivanti:avalanche:*:*:*:*:premise:*:*:* 6.4.2 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*