Path Traversal Vulnerability in Ivanti Avalanche Affects Sensitive Data Security
CVE-2024-13180

7.5HIGH

Key Information:

Vendor
Ivanti
Status
Vendor
CVE Published:
14 January 2025

Summary

Ivanti Avalanche versions prior to 6.4.7 are susceptible to a path traversal vulnerability that enables remote unauthenticated attackers to access restricted files, potentially leading to the unauthorized disclosure of sensitive information. This vulnerability arises from incomplete mitigations implemented in a prior CVE, highlighting the need for users to promptly update to the latest version to ensure their data remains secure.

Affected Version(s)

Avalanche 6.4.7

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.