CVE-2023-46263: Ivanti Avalanche Arbitrary File Upload Vulnerability
ID: 6e5416aa-4e1e-5077-b216-87f31863da36
STIX ID: report--6e5416aa-4e1e-5077-b216-87f31863da36
Feed Name: Zero Day Initiative (ZDI) Blog
Threat Score
Monitor TCP ports 8080 and 8443 for HTTP POST requests to /AvalancheWeb/app/FileStoreConfig.jsf; if the linkFileStoreConfigSave parameter equals "linkFileStoreConfigSave" and the txtUncPath parameter contains "ProgramData\\Wavelink\\Avalanche", consider the request suspicious as it likely indicates exploitation of a Wavelink Avalanche vulnerability.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
