Unauthorized Access to Arbitrary Files in Ivanti SmartDeviceServer 6.3.1
CVE-2024-38653

7.5HIGH

Key Information:

Vendor
Ivanti
Status
Vendor
CVE Published:
14 August 2024

Summary

An XXE (XML External Entity) vulnerability exists in the SmartDeviceServer component of Ivanti Avalanche 6.3.1. This allows a remote unauthenticated attacker to exploit the issue and gain unauthorized access to read arbitrary files stored on the server. This vulnerability poses a risk to the security of sensitive data managed within the Ivanti Avalanche environment, highlighting the importance of immediate patching and risk mitigation strategies.

Affected Version(s)

Avalanche 6.4.4

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.