Vulnerability record · CVE-2023-32562 · published 10 August 2023
CVE-2023-32562: Ivanti Avalanche unrestricted file upload enables remote code execution
Ivanti · Avalanche
Ivanti Avalanche versions 6.3.x and below contain an unrestricted upload of a file with a dangerous type (CWE-434), which can lead to remote code execution. The flaw is fixed in version 6.4.1. With a critical CVSS score and a network-reachable, unauthenticated attack path, it is a serious risk to exposed Avalanche deployments.
Description
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution. Fixed in version 6.4.1.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network-reachable, unauthenticated remote code execution and high EPSS make this an urgent patch target.
What it is
Ivanti Avalanche versions 6.3.x and below contain an unrestricted upload of a file with a dangerous type (CWE-434), which can lead to remote code execution. The flaw is fixed in version 6.4.1. With a critical CVSS score and a network-reachable, unauthenticated attack path, it is a serious risk to exposed Avalanche deployments.
Impact
An attacker can upload a malicious file and achieve remote code execution on the affected server, gaining full control of confidentiality, integrity and availability.
Attack surface
The vulnerability is network-reachable (AV:N) with low attack complexity and no privileges or user interaction required (PR:N, UI:N), so any host that can reach the Avalanche service can attempt the upload.
Exploitation
The record does not list this CVE in CISA KEV and documents no ransomware use; EPSS is high at roughly 0.456 (98.7th percentile), indicating elevated likelihood of exploitation activity. No public exploit reference is included beyond the vendor advisory.
What to do
- Upgrade Ivanti Avalanche to version 6.4.1 or later as the primary fix.
- Restrict network access to the Avalanche service to trusted management hosts and block it from the internet.
- Enforce file type and content validation on any upload functionality and store uploads outside the web root.
- Monitor and alert on unexpected file creation or execution in Avalanche directories.
- Apply least privilege to the Avalanche service account to limit post-exploitation impact.
Detection
- Monitor Avalanche upload endpoints for files with executable or script extensions and unusual content types.
- Alert on new process creation spawned by the Avalanche service, especially web shells or command interpreters.
- Review file system changes in Avalanche upload and web directories for unexpected files.
- Correlate network requests to Avalanche with subsequent outbound connections or command execution events.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-32562 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-32562), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.