Remote File Delete Vulnerability Leads to Denial-of-Service
CVE-2024-27977

7.1HIGH

Key Information:

Vendor
Ivanti
Status
Vendor
CVE Published:
19 April 2024

Summary

The vulnerability in the web component of Ivanti Avalanche prior to version 6.4.3 enables an authenticated remote attacker to exploit path traversal techniques, resulting in the ability to delete arbitrary files. This can lead to significant disruptions in service, manifesting as Denial-of-Service, and could compromise the integrity and availability of the affected system. Organizations using affected versions should prioritize updating to secure versions to mitigate risks.

Affected Version(s)

Avalanche 6.4.3

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.