Path Traversal Vulnerability in Ivanti Avalanche Software
CVE-2024-13181

9.8CRITICAL

Key Information:

Vendor
Ivanti
Status
Vendor
CVE Published:
14 January 2025

Summary

Ivanti Avalanche versions earlier than 6.4.7 are susceptible to a path traversal vulnerability, allowing remote unauthenticated attackers to bypass authentication procedures. This vulnerability is a result of incomplete patches from a prior security issue, necessitating immediate updates to the affected versions to ensure system integrity.

Affected Version(s)

Avalanche 6.4.7

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.