Unauthenticated Remote Attacker Can Read Sensitive Information in Memory via Out-of-Bounds Read Vulnerability in Ivanti Avalanche Before 6.4.3
CVE-2024-23527
5.3MEDIUM
Summary
An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory.
Affected Version(s)
Avalanche 6.4.3
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Collectors
NVD DatabaseMitre Database