Vulnerability record · CVE-2023-28126 · published 9 May 2023
CVE-2023-28126: Ivanti Avalanche authentication bypass via SetUser method and race condition
Ivanti · Avalanche
Ivanti Avalanche 6.3.x and below contain an authentication bypass. An attacker can exploit the SetUser method or a race condition in the authentication message to gain access without valid credentials. The flaw matters because it exposes the enterprise server to unauthenticated access.
Description
An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain access by exploiting the SetUser method or can exploit the Race Condition in the authentication message.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityAlthough CVSS is medium (5.9), the high EPSS score and unauthenticated network reachability make this a high-priority patching target.
What it is
Ivanti Avalanche 6.3.x and below contain an authentication bypass. An attacker can exploit the SetUser method or a race condition in the authentication message to gain access without valid credentials. The flaw matters because it exposes the enterprise server to unauthenticated access.
Impact
An attacker gains unauthorized access to the Avalanche server, potentially reading sensitive settings and data. The CVSS vector indicates high confidentiality impact with no integrity or availability impact.
Attack surface
The vulnerability is reachable over the network (AV:N) with no authentication (PR:N) and no user interaction (UI:N). Exploitation requires a high-complexity attack (AC:H), consistent with the race condition component.
Exploitation
The CVE is not listed in CISA KEV and no ransomware groups are documented using it. EPSS probability is 0.66659 (99.253 percentile), indicating a high likelihood of exploitation activity, but no public exploit references are provided.
What to do
- Upgrade Ivanti Avalanche to a version later than 6.3.x as recommended by the vendor advisory.
- If immediate patching is not possible, restrict network access to the Avalanche server to trusted management networks only.
- Monitor and audit authentication logs for anomalous SetUser method calls or repeated authentication attempts.
- Apply vendor-provided workarounds or configuration hardening from the Ivanti advisory.
- Review and disable unnecessary exposed methods or services on the Avalanche server.
Detection
- Monitor server logs for unexpected or malformed authentication messages that could indicate race condition attempts.
- Alert on SetUser method invocations from untrusted or unexpected source IP addresses.
- Baseline normal authentication traffic and flag high-frequency or concurrent authentication requests from a single source.
- Use network monitoring to detect attempts to reach Avalanche authentication endpoints from external networks.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-28126 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-28126), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.