cbcvebase.
CVE-2022-36973
published 2023-03-29

CVE-2022-36973: This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is…

PriorityP266high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
6.02%
92.4th percentile
This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the ProfileDaoImpl class. A crafted request can trigger execution of SQL queries composed from a user-supplied string. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-15329.

Affected

2 ranges
VendorProductVersion rangeFixed in
ivantiavalanche
ivantiavalanche>= 6.3.2.3490 < 6.3.46.3.4

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability resides in the `ProfileDaoImpl` class of Ivanti Avalanche; monitor for crafted HTTP requests targeting endpoints that invoke this class, particularly those containing SQL injection payloads in user-supplied string parameters used to compose SQL queries.
  • Authentication bypass via SQL injection (CWE-89) — look for anomalous login or session-establishment requests to Ivanti Avalanche 6.3.2.3490 that succeed without valid credentials, especially those containing SQL metacharacters (e.g., quotes, comment sequences) in authentication-related parameters.
  • ·The vulnerability is confirmed only on Ivanti Avalanche version 6.3.2.3490; detections should be scoped to installations running this specific version.
  • ·Exploitation requires some form of initial authentication interaction (the mechanism is bypassed, not skipped entirely), so detections purely based on unauthenticated access may miss this attack vector.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.09.1CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.