← Vulnerability feed

Vulnerability record · CVE-2023-32562 · published 10 August 2023

CVE-2023-32562: Ivanti Avalanche unrestricted file upload enables remote code execution

Ivanti · Avalanche

Ivanti Avalanche versions 6.3.x and below contain an unrestricted upload of a file with a dangerous type (CWE-434), which can lead to remote code execution. The flaw is fixed in version 6.4.1. With a critical CVSS score and a network-reachable, unauthenticated attack path, it is a serious risk to exposed Avalanche deployments.

9.8 CVSS 3.1 Critical EPSS 46% · top 1.2% CWE-434 · Unrestricted file upload
9.8CVSS 3.1 base score
46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution. Fixed in version 6.4.1.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with network-reachable, unauthenticated remote code execution and high EPSS make this an urgent patch target.

What it is

Ivanti Avalanche versions 6.3.x and below contain an unrestricted upload of a file with a dangerous type (CWE-434), which can lead to remote code execution. The flaw is fixed in version 6.4.1. With a critical CVSS score and a network-reachable, unauthenticated attack path, it is a serious risk to exposed Avalanche deployments.

Impact

An attacker can upload a malicious file and achieve remote code execution on the affected server, gaining full control of confidentiality, integrity and availability.

Attack surface

The vulnerability is network-reachable (AV:N) with low attack complexity and no privileges or user interaction required (PR:N, UI:N), so any host that can reach the Avalanche service can attempt the upload.

Exploitation

The record does not list this CVE in CISA KEV and documents no ransomware use; EPSS is high at roughly 0.456 (98.7th percentile), indicating elevated likelihood of exploitation activity. No public exploit reference is included beyond the vendor advisory.

What to do

  • Upgrade Ivanti Avalanche to version 6.4.1 or later as the primary fix.
  • Restrict network access to the Avalanche service to trusted management hosts and block it from the internet.
  • Enforce file type and content validation on any upload functionality and store uploads outside the web root.
  • Monitor and alert on unexpected file creation or execution in Avalanche directories.
  • Apply least privilege to the Avalanche service account to limit post-exploitation impact.

Detection

  • Monitor Avalanche upload endpoints for files with executable or script extensions and unusual content types.
  • Alert on new process creation spawned by the Avalanche service, especially web shells or command interpreters.
  • Review file system changes in Avalanche upload and web directories for unexpected files.
  • Correlate network requests to Avalanche with subsequent outbound connections or command execution events.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-32562 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-38036Ivanti avalanche classic buffer overflow vulnerabilityA security vulnerability within Ivanti Avalanche Manager before version 6.4.1 may allow an unauthenticated attacker to create a buffer overflow that …EPSS 2.7%9.8CVE-2024-13179Ivanti Avalanche path traversal allows unauthenticated auth bypassIvanti Avalanche before 6.4.7 contains a path traversal flaw (CWE-22) that also enables authentication bypass via an alternate path (CWE-288). A remo…EPSS 63%analysed9.8CVE-2024-13181Ivanti avalanche path traversal vulnerabilityPath Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication. This CVE addresses incompl…EPSS 32%9.8CVE-2024-47010Ivanti avalanche path traversal vulnerabilityPath Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.EPSS 38%9.8CVE-2024-47009Ivanti avalanche path traversal vulnerabilityPath Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.EPSS 1.7%9.8CVE-2024-29204Ivanti avalanche heap-based buffer overflow vulnerabilityA Heap Overflow vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenticated attacker to execute ar…EPSS 4.3%9.8CVE-2024-24996Ivanti avalanche heap-based buffer overflow vulnerabilityA Heap overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to execute ar…EPSS 32%9.8CVE-2024-22061Ivanti avalanche command injection vulnerabilityA Heap Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenticated attacker to execute arb…EPSS 3.6%

Source: NIST National Vulnerability Database (record CVE-2023-32562), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.